There was a thread on this briefly yesterday morning in OT.
Yeah that was my post, which included a screen cap of my own password in clear text. The new forum owners pulled it until they could "figure out what happened."
Now this morning I see a forum announcement claiming that "Our passwords in the database are encrypted and we currently do not have any reason to believe the incident resulted in those being revealed." It then goes on to suggest users change their password. Nothing like a big plate of corporate double speak for breakfast.
The passwords in the database are not encrypted. They are hashed with a very weak md5 hash algorithm, and at least some of them were most definitely revealed. Most of the mods received screen caps of their own email addresses and passwords in email yesterday morning from an interested party who was trying to warn everyone. Several mods/former mods, myself included, verified that the hashes and salts were correct for the passwords.
Message of the day: ignore the forum announcement, change your passwords.