I'm assuming, but im pretty sure sites like this operate by getting stolen credentials to third party shipping sites. think of all the sites like pirateship, shippo etc. if a companies account is hacked, they could create api credentials and just distribute a ton of requests across all the accounts. more accounts / larger orgs that get compromised = less chance of killing the beast