Apparently they pretended to be an employee and the help desk reset the password for them. Once in the door, active directory imploded as usual, with full access they encrypted everything and demanded ransome.
https://specopssoft.com/blog/marks-spencer-ransomware-active...