"The company denied there had been a breach of its data."
This is about as serious a breach as it gets. To have (or claim) zero knowledge of it is pretty bad.
If the details of the story are correct, it would imply the attackers had full database access. I would not be surprised to learn the attack vector was gaining a privileged user's credentials, similar to the Twitter hack.