They said this in the article:
> Sources told Risky Business that the hacker entered using valid credentials