it seems that those who haven't enabled the withdrawal email confirmation are the ones being targeted.
so far i haven't yet read about users, with the security feature enabled, claiming that there was an attempt by someone to withdraw money from their account. I really wonder why i haven't heard any. it's possible that they'll check the security setting first before attempting to withraw.
most of the accounts hacked were new.
no password was strong enough. inside job perhaps? or some unfixed vulnerability.
java was not installed in some of the affected users' computers.
it's not just windows machines that were affected.
withdrawals were initiated from different IP's around the world. TOR? web proxies? VPN?