The research is... kinda bad. Beaumont critzies that Microsoft stores the data... locally in an SQLite database? Because it's "easy to steal with malware" (just like your browser history, etc). Blew up in the media though...
It's no wonder collecting this info is a priority. It will be a goldmine for dataminers with the right correlation. Sure right now it's not collected centrally but I'm sure sooner or later there'll be a quick "just click off this tiny T&C update before you continue" crossing our paths.
Also, it means that this confidential info is now in more places than one. It's no longer sufficient to encrypt a file and lay it on a usb stick in the safe.
And it's also there in centralised place ripe for the taking. Not even any need to scan the system to find valuable information.
That said, yeah, if the user interacts dumping saved passwords is trivial as well.