After reading all that, am I the only one who thinks that sites with security practices that egregious aren't simply fronts or traps for mining this kind of information?
If they were fronts, they wouldn't have done something as stupid and high-visibility as resetting everyone's password; that's the desperate act of someone who doesn't know what he's doing.
Fun thought experiment: What would you do differently if you were to actually set up a front operation solely for the gathering of password/email credentials from unsuspecting users? Would you make it stupid simple for people to hack such as 000webhost? Thereby dodging blame, or would you just leak the data in secret in obfuscated chunks so as not to give away the source?