A message from HBGary Federal: http://www.hbgary.com/
Apparently the S/MIME signatures match just fine ... it is possible they got ahold of their private keys as well to sign messages, but that would be more difficult than hacking the central servers as private keys are stored locally on the clients machine.