From the "Steps we've taken" it sounds like they haven't forced a password reset on compromised accounts. I can understand from a business perspective that would be a harsh way for affect people to find out they were in the breach but it seems reckless to keep compromised hashes in the system.