Just had my creditcard charged by 12xgay.com..
Straight as I am, I never did make this purchase myself, however, the password used is one I would usually use..
The biller is netbiller.com, but somehow a site named
http://www.aro-tech.com/ comes into the picture.. this site, like 12xgay.com, seems shady...
So, it seems like some database with passwords + creditcards has been hacked/stolen/abused/sold whatever...
Another option is that a program is cross selling to this site using a hidden form (read : illegally) ... not sure if that is even possible