Linden Lab, please answer these questions ASAP:
What type of data was compromised in the exploit?  Please enumerate the exact fields of info that was stolen, such as physical address, name, email, etc.
What form of encryption is used for the billing information?  How thoroughly was it encrypted?  (What sort of encryption method, how many bits used for key length, etc.?)
The blog originally stated "encrypted passwords" were stolen, but was later updated to reflect "encrypted payment information."
What kind of information was kept in this?  Transaction history?  Credit card numbers and billing address?
                        