I really wonder how they got in there
Someone could have just been brute forcing the email for the past 5 years. Although if it were that you think the provider would have noticed by now. I can only imagine how many failed attempts it would take for a decent password.
I guess we will just have to enjoy the popcorn and see if he reveals the attack vector.
The lost password reset question was a birthday. Probably would have been easy to crack.
On p2pfoundation the birth date is either 1974 (Jan 1 - September

or 1975 (September 9 - December 31). Watching when the age changed from 38-39 would have given the exact date. That is of course if he was consistent with the birth date.