The attacker used a compromised password to access the company's provisioning system for Managed WordPress