

The AI Fix podcast had a piece about how someone let an AI agent do the coding for them but had a disaster because he gave it access to the production database.
Very funny.
https://theaifix.show/61-replit-panics-deletes-1m-project-ai-gets-gold-at-math-olympiad/
You can check on https://haveibeenpwned.com/
It’s more likely to be that they found out your login credentials, yes.
They might find a site with crappy security where they can try many usernames and passwords without getting blocked or they might actually hack the site and get the password list.
Having a strong password, not reusing passwords and enabling MFA goes a long way towards protecting against those scenarios.