CharlesGrey: Er, correct me if I'm wrong, but this doesn't sound like a case of individual accounts being compromised. In order to obtain account details for several millions of accounts, they must have compromised the servers of MS, Google, Yahoo etc. somehow. Unless by "people" you mean the folks working at Google, Microsoft etc., but they probably know a thing or two about security already. ( At least one would hope so. )
Azhdar: Do you think the targeted accounts used strong passwords? I have a gmail account since 2004 (invitation-only days), but never hacked or affected by such incidents.
So you're saying they just brute-force hacked their way into millions of accounts, not just on Google, but also MS and other major services/sites, without the owners of those services stopping them in the process? Just doesn't seem practical. At best you could do that for an individual account, but not when you're trying to gain access to such massive amounts of user accounts.
Nope, if there's any truth to this whole story, they must have actually accessed Google's/MS's data servers directly. How would you even know that your account was never part of such data leaks? When millions of accounts are stolen, obviously not all of them will actually be used for any shady purposes. I suspect most addresses are simply sold to advertising companies.