- Was your email password strong too?
- Are you sure you NEVER logged into your email from any other place than your home, on a safe computer (ie. never used that email from a mobile device, for example)
I see this as a definite possibility, especially if his email password wasn't very strong. As soon as that MtGox list got out, his email address was out there too. Someone may have brute-forced (or otherwise extracted) his email address password.
Isn't it true that IMAP email/passwords are sent in plaintext unless a secure connection is specified? Maybe someone was sniffing his data when he connected to his mailserver, and retrieved his account password that way...
J., do you have a "Reset password" email from MtGox in your inbox or deleted mail folder? It was probably fully deleted, but you never know... not that it would really solve anything, it would just give confirmation to MagicalTux's investigation.
I could not find such an email, with it's no harder than perosner have deleted them afterwards ... the person may very well delete it entirely using my code.
How could it have been a password by email reset hack? You said you logged into your account after coming back form holiday. If this is true then I'm assuming you used the same password as before you went on holiday and the only way that can happen is if the hacker knew your password to set it back... in which case, would they reset your password?
when I came back from vacation, I logged into my account which I usually do, but I could not use my password, so I had to receive a recovery mail from MT Gox, I did and wrote my password again and came in as I wont ... but quickly discovered that something was wrong because everything was in both 0 and $ bitcoins ...
so I went into history and saw that it was sold and move a lot of money and bitcoins.