Even in this dual-homed setup, there is still the potential for the cameras to infect, or otherwise compromise the recording server, which itself generally has access to a much larger part of the organizations networks, if not the internet directly.
At this point, Hikvision has a well documented record of severe cyber security flaws, and countless public statements attempting to deny or downplay them. They are funded by the Chinese government as well. We have seen plenty of other examples of various governments utilizing vulnerable devices, like IP cameras, to gain access to networks, exfiltrate data, or perform other malicious acts.
There are many other good, cost-effective, alternatives to Hikvision that do not come with the legacy of vulnerabilities, and the risks of being closed tied to the Chinese government. Hikvision has brought this upon themselves.
As for how they were alerted, there have been publications documenting Hikvision's risks for years now. I started some of these back in 2017, including this from 2018: https://ipvm.com/reports/hik-hack-map