You're right. It was probably a brute force since they don't have maximum login attempts. http://blogs.skype.com/wp-admin
Also considering that their Twitter and Facebook accounts were also compromised, your assumption that it was the blog itself that was compromised is a big one. I don't have any first hand knowledge on that though personally, I'm just saying.
Here's a proper solution to secure your account: http://wordpress.org/plugins/google-authenticator/
It is 2014, you better prepare a good PR response for when you get breached OR start implementing stronger authentication ASAP.