June/July of 2014, actually, we found someone referencing the actual password dump file being circulated. (Which is why we haven't named them in top level comments yet, because until we're absolutely sure we've got everyone who's vulnerable sorted out we're trying to minimize the motivation for malicious people to go find that dump file and start exploiting it, but apparently they've finally realized that we're going to do their disclosure for them once we do and started taking mitigation steps themselves.)
no subject