Nintendo said a total of 300k accounts have been hacked
edition.cnn.com
edition.cnn.com
Even some of Nintendo's top brass have had strong software engineering skills: in the late 1990s, during the development of Pokemon Gold & Silver, the team was struggling so future Nintendo President Satoru Iwata developed and implemented a compression algorithm.
The skills are certainly there.
You’d think after this they would just buy Auth0.com and use their skills.
Corporate Japan has also lagged behind western companies in this area. The book Business Management and Cybersecurity by Shinichi Yokohama dives into this.
The "attack" was a standard credential stuffing attack (https://en.wikipedia.org/wiki/Credential_stuffing).
Attackers were just using credentials that were leaked in other data breaches to access Nintendo Accounts (Switch and mobile apps), by logging in via a linked Nintendo Network ID (3DS and Wii U).
If the password for your NNID had not been breached in the past (and then reused for the NNID), you wouldn't have been vulnerable. Enabling 2FA would also have protected you against this attack.
Nintendo has solved this by:
a) Resetting NNID passwords when they think someone has been affected
b) Disabling the option to log in to Nintendo Accounts using the NNID username/password.