Agree. In cases like this, organizations will seize on any language or phrasing that implies "not our fault."
Of course just because something is illegal does not mean you shouldn't be trying to prevent it. See: money, banks, theft.
Without igniting a huge argument hinging on the (incorrect) notion that I think providers like PSN aren't responsible for the safety of their users data: we don't tend to focus stories about bank theft on the ineptitude of the banks. We tend to focus them on the criminals who commit the bank thefts.
On the flip side, banks tend to be at least somewhat competent. We don't know much about this particular hack, but some things are just embarrassing - plaintext passwords ;-), but also stuff like putting AT&T putting iPhone subscribers' data on publicly-accessible incrementing URLs (e.g. http://security.goatse.fr/hypocrites-and-pharisees - keep your salt shaker handy.)
This is similar to how organizations tend to use phrases such as "we regret..." as opposed to one's such as "we're sorry...". This way they have their PR move without actually admitting to any wrongdoing on their part. Sort of a semantically plausible deniability, I think.