I mean for the 14,000 accounts accessed with compromised login credentials, yes that's logical that it's their fault.
But what kind of feature would allow attackers to then get access to 7 million accounts from 14,000 compromised accounts? The article doesn't say and I can't imagine any feature that would allow that without being an egregious breach of security.