According to the official Second Life blog a security breach was discovered on September 6.
Apparently, a hacker had managed to get into the game's database through the web servers.
The exploit was shut down but the hacker could have seen a lot of information, including passwords. This data seen by the hacker included 'Second Life' account names, real life names and contact information, along with encrypted account passwords and encrypted payment information. The hacker is not thought to have gotten away with any credit card information.
Second Life has invalidated all customer account passwords and told users to create new ones.
More here. µ