Most common is that a server has been compromised in my opinion.
The password file is then there for the taking (or the NATS database depending on what you have).
I was talking to John Scarpa at Swiftwill and he told me that every server that has been moved over to them is gone through by his team, and every one of them had been compromised. EVERY one of them!
That was pretty shocking to me.
I've also found that a lot of people don't have secure email.
I use phantomfrog to catch and stop all that password abuse, and when I see a particular person's user/pass getting slammed constantly, I contact them. I tell them to change their email password and that usually stops their user/pass from being abused instantly.
Had a lot of members thank me profusely for showing them that their email account had been hacked...
|