From my reading of this thread, it seems that nobody has mentioned this possibility, unless I overlooked it: Given that there definitely was a web server exploit a while back, it's entirely possible that someone used the exploit to grab hundreds or thousands of people's info but did not use all of this information right away. Instead, they could have stored it and tried a few at a time, knowing that most people do not change their login credentials often and that many people never even knew there was such an exploit.
So you're playing along and everything is great, then suddenly ten months (number pulled out of my ass) later your accounts get jacked. Your system is clean, you have never shared your account with anyone, but you are screwed all the same. I would see this as being similar to mass theft of credit card numbers; a bank or business is compromised, thousands of numbers are stolen and dispersed, and six months later your American Express card is used to pay for airline tickets in China.
Edit: This could also be used to put fear into people. You crack someone's account using some method, then track them online. "Gimme 100 million or I'll hack you!" They refuse, you message them their login info and cause them to disconnect. They may think you cracked their account using the trade window or whatever, but in actuality you had all their info before you ever talked to them.
Summary: If the web site exploit was known, someone could have written a script to perform it on mass quantities of accounts, stockpiling the info for use further down the road when the heat died down.
So you're playing along and everything is great, then suddenly ten months (number pulled out of my ass) later your accounts get jacked. Your system is clean, you have never shared your account with anyone, but you are screwed all the same. I would see this as being similar to mass theft of credit card numbers; a bank or business is compromised, thousands of numbers are stolen and dispersed, and six months later your American Express card is used to pay for airline tickets in China.
Edit: This could also be used to put fear into people. You crack someone's account using some method, then track them online. "Gimme 100 million or I'll hack you!" They refuse, you message them their login info and cause them to disconnect. They may think you cracked their account using the trade window or whatever, but in actuality you had all their info before you ever talked to them.
Summary: If the web site exploit was known, someone could have written a script to perform it on mass quantities of accounts, stockpiling the info for use further down the road when the heat died down.

