Matrix.org publishes timeline after security breach:
https://matrix.org/blog/2019/04/11/security-incident/
– the attacker exploited vulnerabilities in Jenkins
– the attacker had full database access, including access to unencrypted content like private messages, passwords hashes, access tokens
– Matrix.org recommends changing your password (including NickServ password)