This was an XSS attack. A malicious script was executed inside an admin’s already authenticated browser context, allowing said malicious script to place itself into public facing pages. Nothing to do with any browser fingerprinting nonsense you’re going on about.
I've seen a few obvious LLM spammers get banned minutes after reporting. Dang does good work.