Yea not sure who approved the PRs that got merged exposing those auth fields... Its not really a data breach like the CEO claims but simply their in house API that exposes auth fields for any and all users.
Either this was done intentionally by a employee, a huge oversight in a code review, or possibly a junior engineer's poc that got pushed to prod by mistake