I received this email today - why would they need a new password for authentication changes? Surely even though the method has changed the pass remains the same, still held in /etc/passwd or /etc/shadow. And if they are switching to shadowing then just cp /etc/passwd /etc/shadow...
Does anyone here want to cast some light on this?