> According to the hacker, access was initially obtained using a leaked password belonging to a former employee of a small Danish company.

So the password could have been 32 alphanumerics with special characters and there still would have been a breach.

The password was not the problem here.

There are typically quite a few steps between initial access and domain domination, which I assume is what they ended up with, considering they have administrator account passwords. Well, unless you are using 123456 as the password for an admin account.

Yes and no.

The problem with the compromised platform is that it had no MFA. If they had just had something like OAuth via google workspace or something, this most likely could have been avoided. But it seems like they just had completely vanilla email/password auth with zero additional security measures.