This is true. I'm not sure there's a good way to deal with all possible attacks like this.

As an aside, I often go to sites that have "mail me my password" features, request my password, and then realize I signed up under a different name. Then I wonder what the guy who just got the password reminder mail is thinking.