but why do they say "hacked" , can't even call it social engineering when it was just a case of his boss not changing the password.
Not quite:

While his account had been disabled after he was fired, he'd been using another employee's account to cause the chaos.
How did he get a hold of that? Social engineering, keylogger, carelessness?

It is fairly common practice in small outfits to have a common password for common applications and they never think of changing those when someone leaves. It would not be that simple in this case as it is a web based service managed by a third party, so I would expect that one customer has one account and one password for it? More information here:

http://www.wired.com/threatlevel/201...r-bricks-cars/

They traced him from his IP, so he must have accessed remotely and been able to log on to the server on which his account had been closed. I am guessing that there is a secure link between the web service supplier and its customers.

I would expect the court to take the view that this was a malicious criminal act on the part of an individual. I don't know about Texas, but over here an employer would not be held liable for a deliberate and malicious criminal act on the part of an ex-employee, even if their resources were used.