If someone set out to write a textbook on how NOT to respond to a security incident, the recent breach at PlentyOfFish.com could serve as a template. Lenny Zeltser explains why at the Internet Storm Center.
(In addition to Lenny’s excellent points, Brian Krebs points out that storing user passwords in plaintext is also a pretty stupid thing to do. What is this, a WWIV BBS in 1994?)