It may be that the attackers pwned the servers and skimmed the numbers (including CVV) as they were HTTP POSTed in plain text.
[0] http://arstechnica.com/gaming/news/2011/02/report-psn-hacked...
The numbers probably also cross the wire in plain text between the web server and the database too.
Why on earth would you ever do that?