You probably don't remember the RockYou fiasco as it happened in late 2009. In case you don't, social game developer RockYou suffered a serious SQL injection flaw on its flagship website. Worse, the company was storing user details in plain text. As a result, tens of millions of login details, including those belonging to minors, were stolen and published online. Now, RockYou has finally settled with the Federal Trade Commission.
http://www.zdnet.com/blog/security/...000-for-storing-user-data-in-plain-text/11274
http://www.zdnet.com/blog/security/...000-for-storing-user-data-in-plain-text/11274