His ADSL router is probably configured with the default admin username and password. Somebody hacked into his router and got the ADSL username/password.
Why are most of the ADSL router manafacturers so stupid. They can avoid this problem by simply disabling (default) access to the router admin screen from the WAN port.
It's very easy for someone with a wifi card to use someone else's bandwidth if the default router username and password are not changed. Although it is stupid that it is so easy to hack, every adsl user should be aware of the risk by now and should change the defaults.