Yes with the NATS programs that had this problem (not all did).. A Webmasters account data, all of it, from name, addy, check details, ssn/tax id, icq, referring urls, and of course email address.
It appears they harvested emails and member user/pass details, but again they did have access to everything.
|