Hackers breached DreamHost's database.
Hackers gained access to the accounts of customers of the American hosting company DreamHost. As a result of this attack, the company initiated a forced password reset.
The company has been using encrypted FTP/shell password protection for the past few years. Previously, passwords were stored publicly. Lists of these passwords remain on the company's servers, but most are no longer current.
As a result of the attack, hackers obtained both new and old tables containing user data, including passwords.
Experts believe that hackers gained access to the database as early as November 2011 through the quick installation system for WordPress and Drupal content management systems.
DreamHost management also recommends that its clients change their email password, especially if it matches their hosting password.