I think the perspective that because a service is "free" means it's security is more lax is a misnomer. Yes, Playstation Network had a large scale database hacking occur in the April of 2011, but that could have easily been any company, including Microsoft.
Account hacking has happened on...