Suspicious wording, if indeed "The four servers were quietly secured the next day.". Normally the PR response would have emphasised that e.g. "we took action immeiately and resolved the problem within 24 hours".
And as for "non-authorized IP address" - really? Is IP address whitelisting used to secure this stuff? And if so, then how on earth did an unauthorized IP address get through?
And then "the company downplayed the exposure, saying the data was less than half a percent of its cloud service" - but according to TFA that 0.5% included the master keys!?!
At the least, their public responses are feeble and imprecise.
Which leads to the suspicion that something darker happened.