Someone please explain to me
. . how an external hacker without any contact (accomplice) in the company could totally wipe all production servers and all backup servers in one go, without ever being detected ?
Okay, forget the detection part - the IT admins could be clueless - but that does not go with the fact that they had different credentials for different servers. They were at least doing something right.
And why go and nuke everything if you're just a hacker ? That's not going to make you any money.
This smells very strongly of an inside job. Done by a state-level actor or not, this is not some group out of Sevastopol just having some fun.