I didn't feel like my assumptions were that big.
From the original article:
> “They use sweeps to collect data from all users of web forums. The use of these techniques could easily lead to mass surveillance by the government.”
Which implies that they are not scanning traffic constantly but are instead performing a sweep across the fora and gathering all data. Which implies querying the databases on a schedule and pulling info as the full dataset nevers exists in the ephemeral traffic.
> “They acquire MySQL databases via CNE access”
Which states that they exploit something on the network to "acquire" the data from MySQL databases.
Those two things together suggest periodic access to the databases.
And given the previous behaviour from accessing networks and hardware without permission of the companies operating on those networks (the Google dark fibre intercept) it isn't too much of a stretch to imagine a similar scenario that could give them access to these databases without asking first.
And the easiest way to get access to a large volume of forums would be to use a common platform as the attack point: A common deployment (cPanel, Plesk, etc) or a common technology that could give up credentials (memcached).
Of course they could use a vulnerability in MySQL, but I bet that's harder work than just trying default passwords or pulling credentials from the unsecured memory cache.