To emphasize something though - the passwords weren't "discovered" they were handed to the "hackers" by the account holders. My mom got several emails from "hotmail" (or MS, or someone) that insisted that she had to click on a link and "verify" her address and password or they'd shut down her account.
This same stuff has been done for ebay accounts, gmail, hotmail, yahoo, and just about every bank imaginable.
Internet Rule #1: your ISP, email provider, ebay, or bank is <span style="font-style: italic">not</span> going to email you demanding that you tell them who you are. If someone knocked on your door at 6pm and said "hi, I'm from your bank and I need to verify who you are, please write down your full name and all your bank account numbers" would you do it? Of course not.
Whew. Glad I got that off my chest. Have to run now, some African prince needs my help laundering money.