No exploit and no zero-day. An account existed, it had a guessable password, and nobody had required a second factor on it.
Nobody attacked anything. A sharing mechanism offered a wider scope than the task needed.
A token signed with a trusted key is not a forgery the platform can detect. It is a valid token.
The encryption step was always optional. Drop it and you keep the reputational leverage for a fraction of the work.