WPEngine, one of the largest WordPress hosting companies, has discovered a leak of customer credentials. The company carefully avoids mentioning the word hacking in its statement, but it still clearly mentions the data leak. 
Let's see what the announcement says:
At WPEngine, we are committed to providing strong security. We are writing today to inform you that we have a report that includes some of our customers' credentials. We are vigilant, proactive, and taking security measures across our entire customer base.
We have already started an investigation, however we need to take immediate action. Furthermore, there is nothing that requires your immediate attention.
While we have no evidence that the leaked information was misused, as a precautionary measure, we are canceling the following five passwords associated with your WP Engine account. This means you will need to reset each of them. Instructions on how to reset these passwords are at the bottom of this email.
In the WPengine portal
In the WordPress database
In SFTP
In the original WP-Admin Account
In all Password Protected Installs
As a security best practice, we also recommend that if you use this password elsewhere with other applications, you change it immediately.
We apologize for any inconvenience this may cause. We take this report as an opportunity to review and strengthen our security and remain committed to strong internal security practices and procedures.
We take the security of our customers very seriously. You can get more information about the event from the page https://wpengine.com/infosec
