On top of that, how does getting access to someone's bank account even help you? You have to transfer the money to another account, which leaves a trail...
In that case, E*Trade detected the activity as fraudulent, so the damage was minimal.
The more password databases are hacked, the better password cracking becomes, and the more sites black hats get access to. It's a vicious cycle. Yes, people sometimes do get large amounts withdrawn from bank accounts.
http://arstechnica.com/security/2012/08/passwords-under-assa...
The simplified version: Every time a password is cracked it is added to a database of hashes used to hack other databases. Essentially crowdsourced cracking.
http://www.theregister.co.uk/2012/06/07/linkedin_admits_data...
Also, since it's vanilla http, you could sniff these passwords at a coffee shop's wifi all day and just wait for someone to log in to Pandora.
So there's the chance of gaining access to other accounts as a result of the data leak... such as their bank accounts, etc.