> What were they running, Windows XP with 2-year old chrome browser?
Like many consumers: iOS with automatic updates turned on. It’s not news, either; there are groups who discover and use 0-day exploits in order to allow their customers -- usually a government -- to infiltrate a target smart phone -- by phone number, no less -- and install spyware on it.
NSO Group in particular made the news in the past few years because their software was used against the devices of US government employees, which goes against the contract they had/have with the US government. Famously, a journalist was targeted with their software and subsequently gunned down at a gas station, naturally because they had their phone on them, which was used as a real-time location tracker by the assassination group.
Luckily, most people aren’t investigative journalists so there’s a small worry about assassination. Unluckily, there’s a lot of global organized crime, which ends up paying well for those who do impactful work... like perhaps finding a Safari/iOS vulnerability or a camera/iOS vulnerability and exploiting it to exfiltrate bank account credentials.