I was a victim of this same attack today. I woke up to read a password reset email that I didn't request. I can't log in and the password reset link didn't work either. Although it did say in the reset email that Gox's main support days are Monday to Friday I replied to the reset email saying I didn't request it. And they got back to me in about an hour and said: "We apologize for the inconvenience caused. We have disabled the withdrawals on the account and we are investigating further on this. We will keep you updated."
Exact same story here. My account should be safe though thanks to Yubikey. I'm pretty confident that neither my mail server nor my client machine was compromised but of course there's no way to be 100% sure.
I think the OP's theory that someone can access Gox's password reset mails has some merit.
+1
Here the details from my case:
Time: Sat 13 Jul 2013 07:08:17 AM GMT
IP: 173.160.58.186
Browser: Opera/9.80 (Windows NT 6.1; WOW64) Presto/2.12.388 Version/12.15