The article mentions that the intrusions involved a security hole in PHPMyAdmin, so, likely neither (unless the attackers just got access to the database through PHPMyAdmin using the default admin password rather than a security hole).
Why isn't using PHP for security sensitive work considered illegal yet?
PHPMyAdmin is just some software used by clueless neophytes, not part of PHP. Similarly poorly written and insecure software is surely possible with Ruby, Python, you name it.