I don't know it is a reason or just a fake one, used by the user to fool us but let's say, reuse password is bad practice.
I don't believe admin of Altcoinstalks forum plays bad and do something like this with his forum members but who knows. And let's take this case to make a warning, again
Sound like too much of a stretch, if anyone with access to that data would have had really malicious intents he wouldn't have opened a loan request from an active user, they would have ta lot of other things too and for sure not acted just as soon as they got the pass for $300 knowing they will be the fist to have the fingers pointing at them. But leaving altcoinstalk side, another compromised platform might be indeed plausible, all the users should check if their email isn't already on some pawned list , with so many scam shitty offers around here I wouldn't be surprised if more haven't already entered the same credentials to dozens of sites.
Of course, there are a few other explanations for this but I'm not going to create a shitstorm by mentioning them, I'm leaving that to some other unlucky bastard!
Unfortunately, I have accepted one of them. I am worried about the access of those accounts without changing the password.
Will be a bit of pain in the ass for the eons asking for a loan but make it mandatory to ask for a loan with a signed message from an used address on this forum, at that point you don't have to look for suspicious activity and waste your time wondering every moment if this is the real guy while siding hundreds of "is this really you?" messages.
Plus there won't be any kind of 'it wasn't me" situations where you get scammed of some $.