No, the internet access was down to finding a 0 day exploit in artifactory. However this was only get requests and they had to then use a url shortener to use other methods, then used a cybergym instance they found to run more long running things.
Assuming there were no exploitable systems that had network access. We’re already talking about a case where based on software forbidding access they still had access. Why would a firewall be different? Harder sure but its only at the level of “as far as we know no way of getting past this”.