IIRC, it’s common to not throw a vendor under the bus if they properly disclose the breach so as to not discourage reporting of breaches. Healthier for the unfortunate ecosystem.
This is not a “breach” the article hints at a trojan which scrapes or exfiltrates credentials off of user computers not a singular provider’s database.