I gone through a funny theory, I won't publish any details tho:
1) The bans are based on the users' account and console ID's.
2) We can modify all traffic sent and received by the PlayStation3
What if some skiddies start to modify their sent traffic to appear as another user and use backups?
The PSN servers would recognize the TOS violation and check the online user database for known connections based on the ID's. The user and his consoles who really owns the ID's would be banned.
Even a simple Windows application which goes through ALL ID's may be possible. 24 hours and any console worldwide would be banned.