API leak is one hypothesis, another one is that they got a mole there too.
The same goes to Facebook. A number of FB users got detained in China with no better explanation than MSS getting access to FB's internal information like phone ID and IMSI data in user database.
The most probable explanation people have crafted is following:
1. Using internal or external tips, MSS gets user account info of a person of interest
2. Their mole accesses the user database for info on cookies, IMSI, advertising ID and such
3. MSS than cross-references the data with data on the open market, like IMSI databases sold by mobile advertising companies
4. One way ticket to Heilongjiang is issued the next day, once the identity of the person is confirmed using logs of phone companies or ISPs.