"Correlation does not imply causation" comes to mind; even if someone who has clicked a suspicious shop later has their account accessed by a hostile party, that doesn't mean it's the cause!
The claim that opening the shop is the cause, sounds like the sort of rumour started by someone who assumed they were connected, rather than actually found evidence. It felt like an unlikely theory to begin with, and those packet logs further support dismissing it...
Keyloggers or social engineering sound far more likely to me. I'm not sure people often understand attacks like say... 'get target to sign up for a forum where you have disabled password encryption, then try their login details on mabi'. It fails of course on someone who uses different passwords in each place, but not everyone does that.