Took a snapshot of the page on archive in the event the poster deletes the post, since it sounds like its a leak from internal IT. The scope of this attack could be corp IT vs production systems. I would hope that the authentication domain is not shared between their corp desktops/laptops and their production web environments.
https://archive.vn/3zWoE
Related HN Post: https://news.ycombinator.com/item?id=23926289