I can't tell you exactly how, but the company probably just had a weak firewall and he exploited it to gain entry into their data files. Good hackers that are determined can get into almost any computers that are connected to the Internet. Security is a relative thing.
If you are interested in finding out how easy it is for a hacker to "see" your computer or network go here: https://www.grc.com/x/ne.dll?bh0bkyd2
Click on proceed (it is a safe and very useful place) then click on the All Service Ports button in the middle of the top silver row.
Ideally, your computer will be completely stealthed. If a hacker can see you, he knows where you are and I guarantee that he can get into your computer if he wants to spend the time, although most entry nowadays is via inadvertently downloading a rootkit or other malware.