How were the credentials stolen?
Read from the ENV variables of a container.
And someone was stupid enough to put a reusable tailscale auth key in there.