In the disclosure it says that the attack included names, email addresses and phone numbers. It did not contain any passwords or social security numbers, so your passwords must have been compromised in some other way.
(But in all likelihood the poster's account was just compromised through the usual means, otherwise there would be more reports of hacked accounts.)
Do you have any evidence that the action here by the new leadership to disclose all breaches was disingenuous?