This happened on a vB board I'm a member of a few weeks ago. The server was compromised and a harvesting script that prompted usernames and passwords to be entered was planted on the homepage.
These were logged to a txt file and later published online with everyones usernames and passwords.
The amount of times a member tried to login was how many times they appeared on the list in the txt file.
This is the reason why your username/passwords are in plain text format. They remain encrypted in the database.
Get in touch with your host and shut down everything. When your back up make every user change there password.
|