Update: I got a call from IHG today. As the poster above noted, I had the choice of keeping my old number and giving a new email address or getting a whole new Rewards Club number.
IHG redeposited all my points and was able to cancel the Amazon Gift cards the fraudsters had ordered before they redeemed them.
In resetting my pin, I noticed all the personal information (birthday, passport info, and address/phone info contained in the account. Wow! I can only wonder where all that is now. I reiterated to the agent that they need to improve their site security and she said they are working on it... We'll see.