How were the iCloud accounts then attacked if they didn't have physical access to the device?
The passcode is “tangled” with the device’s UID, so brute-force attempts must be per-formed on the device under attack
Even with the password you need the device, which they didn't.