The haveibeenpwned description says password hashes are md5, which sucks. But phpBB has used bcrypt by default since version 3.1 (2014)... I wonder if all the hashes are md5 or only those for older accounts?
I used to like it back in the day; I even met my roommate (when I had one) there.
Could that have been a honeypot? At least partly? That's something xkcd would do.
The trick to remembering them is to use them regularly. This is also why I don't use a passphrase: a password is much shorter and less frequently typo'd, thus less annoying for frequent use.