I am sure glad I switched to ProtonMail.
Protonmail stores all your emails encrypted, with the encryption dependent on your password, so something like this couldn't happen there.
Reasoning:
Are emails automatically encrypted with a hash of the user password when they are received?
If the user forgets the password, how do password resets work?
Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be needed to log in with in the first place) to unencrypt the older emails, and re-encrypt with the newer password?
It certainly is something that users should probably be aware of. At least I would...