Reminds me of an incident I had with my account at NeSol some years ago. I used to get promotional cards in the mail from them, always in pairs, one addressed to my login account name and the other addressed to my password. It seemed inconceivable and I could never get them to actually believe me, even with scanned proof.
No matter the policy or level of security behind internal tools, it still potentially can leave more room for such errors.