Apparently Sony doesn't really rate-limit logins (say, per IP), leaving their customers open to password bruteforce attempts. One would hope - but, sadly, not expect - that they would learn...
On the positives, at least they're being open about it now and they detected it.
I'd love to know from someone in the business whether bruteforce attempts like this typically come from a single IP, multiple IPs or a unique IP per account break-in attempt. If it's anything but the latter, one would really hope a company as high-profile and as targeted as Sony would be checking more thoroughly for this kind of stuff.