contact microsoft and tell them what has been going on. also contact your credit card company and inform them that the purchases are fradulent. since it is over digital distribution you may not be able to get your money back, but the sooner you contact them the sooner they can put a stop to the illegal purchases.
also, since a proxy cant be used with xbox live (or at least it cant as far as i know) then the person is using their REAL ip address, which means ms CAN track them easily, meaning if you dont get your money back from ms you will be able to sue the person doing it and potentially get back more than they stole from you.
the sooner you contact ms and your credit card company the sooner you can put a stop to all of this and have your account back.