@dangoodin one thing their writeup doesnt make clear, is that they were corporate credentials.
thats the only way that you can draw a dotted line from "some test vm somewhere with some kind of creds" to "execs and security team emails".
they refer to it as 'tenant', but there are only two possible explanations for what happened:
1) it was indeed 'customer gear', but staff logged into it for some reason
2) it was corp gear, and they're just calling it 'tenant'.