It's not quite what it seems. The passwords got into log files before the passwords were stored in the password database, and someone got a hold of the log files.
I suspect that this is far more common than people realize (sensitive data getting into log file, not log files getting leaked).