If there is money to be made someone will figure it out.
So emails were stolen what does that do? they cant get into your account all they can do is spam you maybe you can try not clicking the key logger link?
It was obviously pretty good security if the hacker got into there system yet didn't actually get much (Im sure the hacker thought he had more than he actually did)
If you look at other recent company's for example Sony or the worse but not as well known Valve breach. You know it took Valve 4 weeks to tell people that there credit card info was "probably" stolen? lol