AIUI the .mac account was the backup email address of the Gmail account. So
1. The attacker compromised the .mac account.
2. The attacker used the I forgot my password feature of Gmail - to get an account reset email for the gmail account sent to the .mac account.