Just had my account logged into from a Tor exit node 4 mins ago, was a unique, 160bit password not used on any other site and stored in a keepass vault on a managed device.
Initially was sent an email stating a logon had come from 185.100.85.61 followed by a second email one minute later requesting a change of email address on the account to
gamesystm1a@dr.comHave intentionally locked out the account by keying incorrect password three times but not holding my breath for support to respond.
Edit : Best I can gather this may have been an implementation fault with the changes documented here
https://btc-e.com/news/233 - I *do* however have 2-factor auth on the email address used for the site so this is not a direct email breach.