Well this one is a bit different, and concerning. Device credentials were targeted as opposed to web account credentials.
Not a lot published so far on this and most of the different sources state the same information.
It will be interesting to see where this one ends up