It got worse.
The attackers got into the (supposedly) standalone property management system that was supposed to only accessible at the front desk itself, or by the owner logging in remotely with an app that the front desk clerk would see in use. I saw no such activity when they tried another...