From what the article said, I understood the hard drive the wallet was on was encrypted. Once mounted, the wallet would be accessible to anyone with login access to the OS.
I don't understand how they got into his computer in the first place. No amount of 2FA breaching could possibly get somebody into my Windows machine remotely. And not having a password for his wallet makes nonsense whatsoever. I'm thinking Forbes has something wrong.
Going by the article, gaining access to his Microsoft account was enough to provide access to his Windows machine. I'm not sure I'd trust Forbes to get this right, but a quick googling indicates that having access to the MS account the main Windows user is linked to will let you recover the admin password.