Consider this a PSA to all those using Dreamhost. 3,500 passwords have been leaked, and numerous sites have been compromised already. Here is the word from Dreamhost themselves:
“We’re still working to determine how this occurred, but it appears
that a 3rd party found a way to obtain the password information
associated with approximately 3,500 separate FTP accounts and has
used that information to append data to the index files of customer
sites using automated scripts (primarily for search engine
optimization purposes).”
How FTP passwords are so easily leaked is beyond me. It’s not as though they are non-encrypted, or were they? Regardless, if you are a Dreamhost user, it’s highly recommended that you change your passwords (cPanel + FTP) there as soon as possible, even if you did not receive that e-mail.
Source: Caydel