Like they said in the article, Twitter uses bcrypt to store your password, but many of the passwords in the dump were plain text. This suggests that they were scraped together from external sources (i.e. malware on your machine, re-use of a password from one of the other dumps like LinkedIn). Hence, compromised from outside Twitter.