This was not a case of stolen credentials, but rather of vulnerability exploitation.
I tested the big three so you don't have to.