He said he believes the credentials were stolen in breaches that have yet to be publicly reported.
This really bugs me. It seems like many companies are either completely unaware that a breach has occurred, or know about it and are taking their time notifying customers (for PR or other purposes). Either way, customers are not getting this information in a timely manner, and that needs to change.