According to the article the breach included credit card CVC numbers, which should never be stored. This is a huge deal.
You are describing what could be a reason to keep those CC details but definitely there are other ways to do it, including delegating vaults to third parties.
This is a major fuck-up and there's no way to sugar coat it, I'm afraid.