Place your bets, phishing or bug exploit. Some of these targets are too high profile to all fall for it and probably have teams that manage these accounts securely. Edit: 2fa was bypassed, interesting. https://twitter.com/tylerwinklevoss/status/12834920178892595...
Sounds like an exploit. The article says that some of the accounts were confirmed to have multi-factor authentication enabled.
It sure seems like multi-factor auth isn't very helpful, when nearly all hacks have nothing to do with breaking credentials.