The attack, which came to light on 12 December, involved unauthorised access through the credentials of an IT service provider, Vincit.