Not the worst breach I've ever seen, but a couple of stupid things still. Not least, the reset email linked you to I actually presumed it was a high quality phishing attempt and flagged it as spam. Later down the same email they advised "Never click on 'reset password' requests in emails - instead go directly to the service"...

