Once attackers were logged in, they had full access to any other member's account. Well, props to Hilton for a) releasing a statement quickly and not hiding or mitigating this story and b) fixing it ...