I received a message from Atlassian about my account being compromised:
On 12 February 2017 we detected a suspicious login to your Bitbucket Cloud account. We believe that a malicious actor used a large database of usernames and passwords stolen from third party services to access Bitbucket Cloud accounts. We can't know exactly how your password was first compromised, however it was not caused by Atlassian.
Atlassian is confident it wasn't their fault and speculates it is because I use the same login details elsewhere. However I use a unique password here, which couldn't have been stolen from a third party service. Is Atlassian leaking passwords?