Another Q&A from Sony: http://blog.us.playstation.com/2011/04/27/qa-1-for-playstation-network-and-qriocity-services/ , including confirmation there is a criminal investigation occurring. If that makes it all the way to the courts, should be pretty revealing in what actually happened. They also note that credit card data was encrypted, but other personal data wasn't.

And Gamasutra is reporting some developers have already been sent a new SDK for their dev kits with fixed security. Leading more credence the initial exploit did involve devkit related materials somehow.