Here's a
good writeup of just what exactly went down. For the tldr folks, basically Gawker got itself in a pissing match with 4chan over the summer, and as part of this basically painted a big target on themselves. This seems to have got the attention of a group of blackhats (who claim they are not associated with either 4chan or anonymous) to take notice, and what followed was the result of that. On the security side of things there's a pretty long list of things Gawker did wrong, such as running severely out of date software on their servers, ignoring warning signs their internal systems had been compromised (it looks like they were actually compromised going all the way back to mid November), and waiting way too long to notify their users once they did realize data had been compromised. The passwords were encrypted, but still got out due to Gawker using DES to encrypt them (DES was cracked back in the late 90s). Basically a nice object lesson in how
not to handle security.