"A Million UserNames and Passwords were on their servers? The company has been bad a long time now, very long time. How do they have a Million UserNames/Passwords on their servers?
Maybe Mordac stole the data himself, sold it on and using a fraction of the profit to frame some someone else.
There are only two reasons to store passwords unencrypted (or poorly encrypted so they can be decoded) on your servers.
1) For nefarious purposes (xkcd.com/792)
2) You are an idiot
You count all the users accounts made since day one. And you never really erase a user (although you might tell them that you do). That way even the users that left disgusted after the first login count.