There’s no perfect solution here: publish the raw data, and people who haven’t changed their passwords get cracked, or publish hashed (in some way) passwords, and people will crack the passwords themselves. (That said, I guess most crackers will just get the data straight from the source, but still.)