There don't seem to be any outbound transactions from that address, so Ledger refunded the victims separately instead of sending the funds back. That means they likely don't control the key. OTOH, the funds (worth about $40k for the Ether + another $20k for the tokens) haven't moved at all, so "test key that was lost long ago" does seem plausible. (Especially since it also was used on the testnet before https://ropsten.etherscan.io/address/0xC33B16198DD9FB3bB342d...)
Could of course also be an attacker who was hoping for a bigger loot and didn't want to risk getting caught over $60k, but as you said, not sure what's worse - incompetence or compromise.