And AWS! As the article said he got lucky that the attacker didn't twig that there was an AWS account associated with that amazon.com login.
You should be using two-factor authentication for all your AWS accounts, especially the 'root' account that's tied to your regular Amazon.com login (I've always though this is a bit odd).
You should also never use that root account and set up IAM accounts for yourself and any other user (which also use 2FA).