We deal with such cases, it is rather simple.
- first administrator (such issues are never escalated below administrator level) determine probability of the player saying truth, this is actually easier than it sounds.
- then they send a request to generate a new password to me - game owner (we NEVER give old password also admistrators can not use this option on their own)
- administrator sends the new password to the player
As for determining the validity of the request, it is mostly about common sense.
- does the account became inactive in the last days?
- who can (faction/clan mates) back the claim?
If an account of an active player became inactive in last 48 hours and a high rank person or two from his clan says it is the person in question then it's not much to think about

Also the email still is associated with the acccount (there is no email change option) so the original player (in case of successful scam) can back his claims easily.