Your assumption is pretty accurate. Whatever internet-facing device is compromised is then used as a gateway onto the internal network, and a conduit for getting data back out if necessary. With access to the internal network, it's usually much easier to find things like systems with default/weak passwords, exploitable services, and so on.
It usually takes a couple of steps, like hopping from the initial system onto something that has interesting credentials stored/cached on it, and from there on to the things that are actually of interest. Every once in awhile, I'm lucky, and the initial point of compromise has super-privileged credentials on it, but that just makes things easier.
Take over the thermometer and you can send requests to the database as a whitelisted ip.