I was relieved to see that only internal employee information was impacted. You don't even want to know how many banks, hospitals, and power plants rely on Citrix Receiver for remote desktop access.
Believing that puts a lot of credence in their analytical/forensic/security skills. Which doesn't align well with "inside Citrix for Five Months".