The signed hash matches the original version of the document (sans tenant's signature, sans fraudulent addition). The hash doesn't match any other version of the document.
> Interestingly, the certificate page was identical in both documents, including the checksums, despite the content being different.
I think they took this to mean that the signed copy and the copy with the fraudulent addendum both hashed to the same checksum, but I'm not sure that's what was meant; based on the article it's not obvious to me that OP was able to check the signed checksum, though I can't imagine they didn't try. It's the 'original checksum' field that matched the base.pdf clean document without signature or addendum.