Well if someone got a dump of the DB, and had the password hashes it would be pretty easy to get the password from them, given that vanilla is OS and they could of gotten the salts (probably from the db) if the passwords were salted....I probably shouldn't be surprised by this but I am. Either another security hole was used to commit the hack or they never actually fixed the previous issue.