Maybe so, but in this case they made it easy for them [1]:
> Upon examining those logs, Volexity found that in January and February, password-spray attacks had been carried out against this service and three accounts had been successfully compromised by an attacker.
> ...
> The Enterprise Wi-Fi network, however, did not require MFA and only required a user's valid domain username and password to authenticate
> ...
> While the Guest Wi-Fi network had been believed to be completely isolated from the corporate wired network, where the high-value targeted data resided, there was one system that was accessible from both the Wi-Fi network and the corporate wired network.
Bad passwords, no certificate based network authentication or MFA, bad network separation. Basic stuff.
[1] https://www.volexity.com/blog/2024/11/22/the-nearest-neighbo...
(This should have been the referenced page IMHO.)