They could've blocked source IPs making all the login requests, but that was probably being changed to not set off alarms. However, there wasn't enough information in the article to go on, but since they suffered so many breaches of user accounts, they probably had to do something wrong. I'm too busy to dig into the specifics.