Please see the most recent updates in the "Where did the .com name go?" thread. Posts number 16 and 17.
Dropbox has said that it was not their service that was compromised but third-party services that exposed the credentials. The following statement, given to TNW, is posted below:
Dropbox has not been hacked. These usernames and passwords were unfortunately stolen from other services and used in attempts to log in to Dropbox accounts. We’d previously detected these attacks and the vast majority of the passwords posted have been expired for some time now. All other remaining passwords have been expired as well.
