To make it easier for everyone reading the HN Post Title, they're talking about "Their Server(s) at OVH" being compromised, with no evidence of "OVH" itself (along with all customer servers) being compromised.
Now you may go ahead and read the post.
Now you may go ahead and read the post.
Obviously this is highly speculative.
At the first compromise which may have been external to OVH's systems the attacker may have added their email address to the list of valid emails, and may have received the password reset email at the other email address. This could explain why the second reset password email was unread...