The article glossed over a key detail. He stored his work credentials on his personal 1Password password vault which no one should ever write down nor take passwords home with you. This could have been just a personal thing between him and this hacking group and not involved Disney.
On top of that, it seems Disney was allowing single sign on to Slack. My guess it works sort of like LucidChart where it redirects to like Corporate ADFS or single sign on systems.
I am not clear if Disney has MFA setup for their employees. My work uses ID Authenticator and it’s on my mobile phone.
I don’t know why Disney isn’t using something like Teams.
Anyways just guesses on my part