Based on the names mentioned I searched for their email addresses in password dumps and they all match the large 500M+ lists (anti public and exploit.in - covered here[0]) that have been available on some of the credential-stuffing and hacking forums since late last year. They are aggregate lists composed of MySpace, LinkedIn and other breaches. It appears someone has grepped out parliament.uk emails from those leaks…
We see credential stuffing attacks regularly - some from folks just trying their luck (using known tools and scripts such as Sentry-MBA). Others are a little more advanced and persistent, looking to gather information from successful logins which they can then re-sell on the various shifty marketplaces.
Sites that have monetary value are particularly high value targets. If you have a site which reveals key personal information such as addresses and credit card info (last 4 etc.), these will likely be scraped. If you have a site that can order goods, successful accounts will be scraped to see if they have a valid and active card associated with them, allowing them to be sold for a higher price. If you have a site which collects points (think airlines or hotels), these too will be scraped and sorted, allowing them to market those with higher points for more cash.
Where possible, use 2FA, and always use a different password for each website. Password managers sometimes get a bad name, but they're much better than using the same password everywhere.