I'm surprised they didn't change your password when they hack your account, usually it is the 1st thing they do when they got access to your Account. I guess you got lucky this time they didn't do that and you have enough time to add in a Security Token.

I'm also surprised how they can just pull randomly username and unique password out of thin air. They may have a hacking software, but they have to start somewhere and know some hint and which one to target.