At this point I assumed that it had used my PS3 hardware ID + my (static) IP + whatever to correlate that in all likelihood it must have been a legitimate login, which was already a bit weird but I guess they wanted to make it as simple as possible for everybody.
But this is just outstanding. It's really security 101 failure. As others have pointed out, using a regular password reset email with a unique token would have been much more safe, albeit not foolproof (some people would have lost their emails accounts they used to register by now).
Sony deserves everything that's happening (and will probably continue to happen) to them. The sad part is that I'm sure a majority of the gamers sony really targets must still be chanting "xbox sucks go sony lol" and still think geohot or anonymous or santa is to blame.
-- A very unhappy PS3 (and its ancestors) owner.