Earlier quoted context omitted.
A lot of people use only one password for everywhere... You'd be giving the attacker the keys to the kingdom.
Which is still true if you don't know their passwords but if you have their email. You can reset the passwords for just about every conceivable account they have.
That would grant continued access to the email, and other sites that took protection a little more seriously like Paypal and Bank Logins (you can't reset a Paypal password with just an email, and if you could, such an action would make Paypal fraud detection software go nuts).