the attacker left their IP address in the dump, and their LAN interface address
Edit: it's whoever dumped this as opposed to an attacker
I don't think tumblr have acted on this yet. The other exposed pages have S3 API secret keys, facebook api secret keys, the username and passwords for vimeo, clickatell (whatever that is), twitter oauth secret key, etc. they are going to have to revoke and re-setup each of these.