However, some of these attack groups follow specific patterns, use specific IP addresses, domains, emails, etc. because there is no real consequence to them doing so. Kaspersky, Mandiant et al [1] often have great writeups on these types of things that are often posted to their own blogs and to netsec-related mailing lists that show some of these common attack patterns.
On top of this, Twitter could have been tipped off by law enforcement or intelligence.
With the inside visibility of the traffic across their network Twitter would be able to estimate (whether with their own internal security experts or an outside service) the sophistication of the attacker.
Would expect that at this point there was some discussion with FBI as well. Also, as pointed out, very common for a tech company to be notified by FBI/NSA/police in these situations.
I work with one of the people interviewed in the article, we've been having some fun on Slack with it :)
> I work with one of the people interviewed in the article, we've been having some fun on Slack with it
Ooh boy. I don't think there's much you can do about something like this other than laugh it off, and also maybe recognize that hey, you're probably doing something of influence. (And probably make lots of jokes about APTs.)