With the inside visibility of the traffic across their network Twitter would be able to estimate (whether with their own internal security experts or an outside service) the sophistication of the attacker.
Would expect that at this point there was some discussion with FBI as well. Also, as pointed out, very common for a tech company to be notified by FBI/NSA/police in these situations.
I work with one of the people interviewed in the article, we've been having some fun on Slack with it :)