Sounds like it's just a phishing scheme, not a breach of MS databases. It sucks, but if true it's the result of careless users, not a breach at Microsoft which I'd find more worrying.
For anyone who's worried, post your e-mail address and password so I can see if it's on the list of hacked accounts.
