Over the past 30 days, there has been exactly one hit to action=clientlogin with sensitive data in the query string, and none to action=createaccount, action=linkaccount, and action=changeauthenticationdata. Beginning in 1.29.0-wmf.1 (to be deployed this week) these actions will now begin throwing errors if sensitive fields are included in the query string.
Over the past 30 days, logins have been attempted via action=login for 28 different user names[1] with sensitive data (lgpassword or lgtoken) in the query string. This will continue to work for now; my current plan is to turn that warning into an error on February 15, 2017.
[1]: I can't post the list publicly at this time. If you want to know if you're one of the 28, put your user agent into
https://meta.wikimedia.org/wiki/Special:ApiFeatureUsage and look for "login-params-in-query-string".