One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.
However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.
*facepalm* No, the salt is right there in the file, next to the hash. What the salt does is make it impractical to use precomputed tables, you have to brute force the password. If the password is very weak this does not take long.