Researcher refutes Microsoft's account of hijacked Hotmail passwords

Could botnets, keylogging be to blame for password leaks?
Gregg Keizer


October 7, 2009 (Computerworld) One researcher isn't buying Microsoft's and Google's explanation that hijacked Hotmail and Gmail passwords were obtained in a massive phishing attack.

Mary Landesman, a senior security researcher at San Francisco-based ScanSafe, said it's more likely that the massive lists -- which include approximately 30,000 credentials from Hotmail, Gmail, Yahoo Mail and other sources -- were harvested by botnets that infected PCs with keylogging or data stealing Trojan horses.

More can be found here
Perhaps wasn't phished as a user error but perhaps the result of a hole not fixed (either by user or by MS)?