In the article I read about this it appears that they only found out now. They apparently launched an investigation and discovered the breach after being contacted by the hacker