Regarding how the exploit worked, Chan stated,
This was due to an issue where the group ID could be extracted and/or easily guessed, combined with lack of authentication, leading to being able to craft a request that resulted in being given administration rights to that LINE Official Account.The researcher reported the flaw to Line via their bug bounty program on HackerOne in September 2019. This bug leading to a privilege escalation and achieved a critical severity rating with a score of 9-10. Following his report, LINE worked on a fix to eliminate the flaw.
The vendors awarded a bounty of $4,750 to Chan for reporting the vulnerability.
As elaborated in their advisory, investigations revealed that the attackers behind the hacking campaign abused the compromised accounts to send spammy and phishing messages to permanently hijack LINE accounts.
Following the incident, LINE reset passwords of affected accounts alongside implementing other security measures.
Let us know your thoughts in the comments.