I atteneded a workshop recently and met a few white hats who were talking about commercial internet security.
I was surprised how easy it is to divert password reminders /resets for many major Email providers. Also many other ways of entering the person email account and resetting changing passwords.
But what ever security companies do a lot of hackers simply use social engineering, ie making educated guess about the person to guess the password or trick them into parting with either the password or information which makes it easier to predict what it is.