I'm going to take a punt without reading the article and say either it's The Muskrateers directly harvesting the data, or a massive, obvious vulnerability created by them fucking with shit and not having the experience to know they were creating, or their unvetted server was wide open.... because again these are essentially the Hitler Youth, and they might have some technical training but not enough experience to know what the actual fuck they're doing.
Edit: well....swing and a miss. Was a fair assumption though tbf