I would guess that they are getting access to the email accounts attached to the passwords. Most likely the emails attached to the accounts expire. Satoshi himself was victim of the disaster that is gmx. It's really bad. I've lost access to several gmx email accounts myself. It looks like there is a very short period of inactivity allowed before you risk it getting deleted. Then they could register the same account again and gain access.
Other possibility is database breach from either email or the forum itself.
The incentive to steal BCT accounts is obvious, they have value, specially ranked ones, because of the reputation they have, they usually use it for ICO's, bounties, advertising, and they can also sell it to someone else for BTC.
We really need a way to recover accounts soon. I hope theymos delivers on this somewhere next year.