Earlier this year they claimed to have discovered an NGINX 0-day RCE and tested it against a Canadian bank. Not only was it a big nothing-burger, but they ended up purging their Telegram channel aftwards with claims of infighting (screenshots for posterity: https://imgur.com/a/5AThvTv).
I think it's extremely suspicious, but often times breaches like this aren't through the core platform itself. For example, Equifax was a support site that was hosted and built separately from their main platform.
This whole thing does smell like BS to me, though as well.
You don't need to wait for Troy Hunt to tell you otherwise, even he is not always correct.
[0] https://twitter.com/MayhemDayOne/status/1566748988770066435
>UPDATE: while there is definitely a breach, it is still work in progress to confirm the origin of data, could be a third party.