I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the pandemic and just opened it for the whole internet.
CI runners (usually Jenkins) require a perforce user to function and those users often have very simple passwords, this is compounded by the fact that perforce itself does not have any backoff for brute force attempts.
Perforce assumes that it's being hosted in a secure environment.
The note indicates HR documents were stolen, but I have not seen any evidence of that, it is most likely posturing.