so the question is not: am i allowed to reset your password. but am i allowed to limit your access to my service.
the problem is not what they did and why, but how they did it and how it affected the users.
And the clear answer to me is 'yes'. And the customer can try to sue for non-delivery of service if they like, but probably won't get back much more than the $10 subscription fee.
You're generally liable for the consequences of that access - e.g. if Twitter would have their employees take over Trump's account and post "I'm a doo doo head" every five minutes, then that might result in some legal challenges; or if a PayPal employee made payments impersonating your account, then those payments would constitute fraud; but, in general, your employees accessing user accounts and altering data in them is not prohibited by any laws.
[edit] It would be nice if the downvoters could provide some argumentation why they disagree - I can accept that users should have some rights, but according to the current laws they don't. CFAA protects the owner of the system, who gets to decide what access is authorised and what not.
I have control of a user database for my site. I cannot log in as my users since I don't know their password and the database is hashed. But if I log into the database and change their password, now I know what their password is. And now I can log in as them.