"3 months ago"... And "eBay suggest users chanche their password"... Wait, what? I suggest a policy where important breaches in security are disclosed within a short timeframe.
One reason to hold back this information is if going public would make their investigation harder OR if going public would increase the security risk (e.g. if the security hole used wasn't yet fixed and going public meant disclosing something about how the hackers got access). But according to what had been made public so far this doesn't seem to be the case.
[1] http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-u...