I'm assuming they refer to somebody breaking the encryption algorithm, not brute-forcing their way through them.
This isn't CSI. You don't just throw encrypted text at an implausibly attractive IT guy and wait for him to furrow his brow, declare that it's military-grade encryption that will take him a little while, and then have him decrypt it by the end of the next commercial break. PCI-compliant encryption is the sort of thing that, barring incredible leaps in technology or the discovery of a significant algorithmic weakness, will never be crackable in our lifetime.
That the information had encryption is a good sign.
You might want to rethink this. "Will probably not be crackable in the next twenty years" is more realistic.