The paper file listing [1] from the PC in question shows predictable [conference][year]-paper[incrementing-number] file name pattern. Rather than "insider help" [2], could this be explained via a "leaky endpoint/api" that got scraped?
[2] Quote: "HotCRP does not show you your own submission even if you are a PC member, so how did the de-anonymized reviews and PC comments for Huixiang’s paper end up in his laptop? An insider help seems likely."
It's possible, but there are only a few reviewing systems that are commonly used and their permission systems are robust as far as I know. I think a simpler explanation is that someone in the fraud group has a "higher permission role" than a first-line reviewer, so has access to these. This could be someone who is a general chair, program committee chair, track chair or area chair if the conference is big enough, and often even senior PC members (the metareviewers). All they have to do is perform an export and put it on Dropbox or Google Drive.
I hope I'm missing something.
[1] https://miro.medium.com/max/1400/1*sNC6SuC1v8peYmw6KEcz3g.pn...
[2] Quote: "HotCRP does not show you your own submission even if you are a PC member, so how did the de-anonymized reviews and PC comments for Huixiang’s paper end up in his laptop? An insider help seems likely."