On the other hand, if they've cracked the database and got your hashed/encrypted password, they'll more than likely ignore the password and just access your credit card, bank account, health details etc directly. If the company is lax about passwords, it's pretty unlikely that the rest of the data is encrypted! The only reason password encryption is any more important than any other data is that people tend to re-use passwords, so a hacker of one database can often then access others; or actually impersonate someone else rather than just steal their money / reputation.