My money is on a crontab that executed a simple set of ssh command attacks on the specified date.
As per the article, to destroy "all data, including financial, securities and mortgage information," it would be as simple as an "rm -rf" across multiple servers. Except for one critical item, he would have to have root access on all those servers.
Either the scope of his potential damage was very small, or Fannie Mae had some terrible security and change management policies in place.
I cannot decide which to pick.