Earlier quoted context omitted.
Sounds like an exploit. The article says that some of the accounts were confirmed to have multi-factor authentication enabled.
> multi-factor authentication enabled It sure seems like multi-factor auth isn't very helpful, when nearly all hacks have nothing to do with breaking credentials.
This seems like a big claim to make. My understanding is that by far the most common reason accounts are compromised is password reuse combined with another site being compromised.