Or if this is fake and someone trying to steal your password from PHISHING website?
What do I need to do?
It's true.
Basically, an attacker managed to gain root access to the server and a portion of the database containing users' information was compromised.
There are multiple threads about the incident in the "Meta" section (link) which is probably a better fit for this thread rather than "Development & Technical Discussion".
There is also an official announcement by theymos which goes into more detail about the hack:
https://bitcointalksearch.org/topic/about-the-recent-server-compromise-1067985
It's advisable to change your passwords and weaker passwords are especially vulnerable. If the list of email addresses was compromised/is leaked, then you might see more spam coming into your inbox as well.