This is a good step, but unfortunately all of the actual passwords are still out there, so they need to be changed. I think a better idea would be to establish an easily implemented pattern for "password bankruptcy" that companies could follow in the case of a leak.
What would a password bankruptcy pattern look like? One thought is to invalidate all passwords and fall back on email password recovery when a login is attempted. This leads me to an idea I've tried once - if access to the inbox is equivalent to password credentials, why not use an email to login? By this I mean the web site login is a single field - email address. The system emails a one-click-login URL to the user…
In practice I end up doing this for little used sites because I use either my phone, tablet, and two laptops for browsing the internet.
It's annoying if you work somewhere that doesn't allow access to personal email accounts and you want to log-in to something.