This write-up doesn't actually state where these unobfuscated images came from, so it's not clear to me where (or whether) there are actually unobfuscated images in Air Canada's system. Tools like Glassbox usually mark PII fields with CSS classes to blur/redact fields when the screenshots are taken. It looks like the author may have found password and credit card fields without these CSS classes and manually recreated what the unobfuscated fields would look like with dummy data, but it's also possible to configure these tools to not log entire pages or directories -- this is how payment pages are usually configured, with screenshotting completely disabled.
If the (anonymous) author simply mocked up what these screenshots _might_ look like if they were saved, that's pretty misleading.