They specifically call out credentials used during the attack.
But they should be rotating those regardless. You don't get to say "Maybe the attacker didn't get this credential". You just rotate.
The most generous interpretation is that they have not yet have completed that rotation, and they didn't want to risk putting those credentials into the wild during that process.
---
But all of that aside, I feel like the undercurrent of this comment is that the "safety" rules that providers are pushing are genuinely harmful.
Another point where "if you don't own the model, you can't properly operate the tool" becomes true. Open isn't about profits, it's about capabilities.