Hmm, I don't nominally think of my self as "stunningly gullible."
lets unpack this statement though: However, electronic records, perhaps more than any records, lend themselves to being faked.
It is certainly true that someone can edit and change electronic records and the tampering of such records, unless explicitly protected against, can be made indistinguishable from untampered records. But what is much more difficult is to tamper with records from a wide variety of unrelated sources to show the same thing.
For example, it is certainly possible for me to construct a record that says my "source IP" is KREMVAX[1] and to even have the source IP "logged" at the destination site as the origination point. But it is not possible for me to easily alter the s-flow records at Cogent which shows that the packet originated on a port on a router which is sitting in California. Yes, I can by a VPS in the Ukraine using bitcoin that has gone through several mixers but I cannot completely erase all of the packet sources that lead to that VPS. Yes, I can build an "IP over DNS" tunnel to disguise my traffic to the VPS as "harmless" DNS traffic but I cannot disguise how those DNS packets are propagated in the larger web.
The point I'm trying to make is that if you are a state actor (like the 17 intelligence agencies of the US) and the events leave traces (which they do), it is entirely feasible to unwind packet traces, money paths, and network events to the exact origin point. I was at Google when they Chinese did it to Google and got to watch on the sidelines the amazing amount of resource that could be brought to bear on the problem. And what it more, that incident and others less well publicized have lead to still more infrastructure which is completely passive and observational and captures all packet flows and meta data.
As a result, I find it completely believable that the origin of those attacks can be identified with certainty.
I believe it is reasonable to be skeptical about motivations and or command chain that lead to the attacks.
[1] A stand in for some IP Block allocated to Russia