If you're not holding that motherboard in your hands, then you definitely "don't have accurate information to base a story on" if that story is about inserted extra hardware - the story Bloomberg reported relies on analysis of that motherboard. If you find an anomaly in the dev server but can't open it up to look at the motherboard, then you can blow the whistle that something weird is happening, but you're not qualified to be a source for what Bloomberg claimed unless you have seen some evidence about the actual hardware.
As you say, reporting is about cross-checking documents. In this case, the relevant documents would be the technical details of that malware - photos of the motherboard with the inserted hardware, schematics and analysis of where and how the inserted chip connects to the "real" parts, dumps of the firmware alterations, microscopy analysis of the extra chip after decapping it. Instead, Bloomberg provided "this is where it could have been" CGI illustration and "this is how the mechanism might have been" description of the process. All details about the attack seem to be made up by Bloomberg, they're not based on any real hard data from their sources.
This implies that none of their sources had (or provided to Bloomberg) sufficient detail to assume that this is what happened - if the sources say "well, there was a major supply-chain attack but we're not giving the details" then that's not sufficient to report what the Bloomberg article did, making up the details without knowing them. If the sources provided enough detail to Bloomberg, then this is the point where Bloomberg should release those details to the public.