... would this be a total security breach? Would that person then have access to all passwords, etc.?
yes, passwords only md5 coded
I vageuely remember once over at ubbdesign.com, that the administrator (JC) reset all the users passwords (he also uses Threads) and made all the users request them. I don't know how he did it, resetting the passwords, but it might not hurt to ask.

Or just send an email to all your memebers informing them of the breach and ask them to change their passwords.
Just an SQL command to wipe or set every U_Password to a new value.
© UBB.Developers