Yes, they're not the same thing. First, the credentials were leaked. Then, the service was hacked using the leaked credentials. Afterwards, information obtained in the hack was leaked.
In this case, they weren't exploiting any weakness of the system thus they did not hack. Logging in is an authorized action. Who is using those credentials is another story. Clearly it is a user mistake. It's like leaking your SSN and saying people hacked your credit card.