The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.
That was my thought exactly on reading that line: that is not a backup. (Ok, the word isn't strictly defined, but you know what I mean.) They have said there's a "real" (offline) backup as well, luckily, but that just reinforces that the "pretend" backup was irrelevant and wasn't even worth mentioning in the writeup.
Any guidelines on how to back up such that the attacker cannot reach (when the hacker otherwise had some valid credentials)?