Everyone has their own theory as to what caused them. Most revolve around the same password being used everywhere. I could see someone using the same password at all their sponsors, but ePass also? That to me is far fetched.
I believe the cause was the gMail security holes. It's a more realistic explanation that doesn't involve the victims of theft having done something stupid.
I had made a thread here
http://www.gofuckyourself.com/showthread.php?t=794886
but it got only a lukewarm response.
Here is more info...
http://blogs.zdnet.com/security/?p=554