"By default, you can initiate a password reset by entering only your @username. If you check this box, you will be prompted to enter your email address or phone number if you forget your password."
If you're able to get back your account, enable the "Require personal information to reset my password" option in the twitter account settings. Because you didn't have this option enabled, when your email was compromised all's they had to do was know your twitter username and do a password reset by email.