The article by the OP is slightly vague about the details of the breach. This one goes into more detail: https://www.comparitech.com/blog/vpn-privacy/choice-hotels-d...
But after reading the details, the whole situation looked nothing more than a straight-forward search on SHODAN.io for exposed DBs. A 'ransom' of $4,000 for 700k users is cheap to Choice Hotels compared to the others I've seen demanding $1M+ for the same number of users.
> The MongoDB database was made publicly available with no password or other authentication required to access it.
> The database was left exposed for four days.
Classic.