A better method might be next time they come onto the site and log in (or if they are already logged in), put up a stop page (similar to a paywall message) warning them in plain English of what happened and strongly recommend a password change. Make it easy for them to skip or X out of the box.
I think forcing users to change passwords or taking a passive email stance when there is a chance most might not read their email are both not ideal solutions