It was really interesting because at the time the conclusion of our security consultants was that the attack was just random commercially-motivated prospecting. Then the Citizen Lab Dark Basin report came out years later and it was clear they were after our internal comms, so they could milk a decade of emails for anything that looked bad when taken out of context. Yikes.
After the attack we put a 3 month retention limit on most emails and messages. I recommend this to anyone doing sensitive work! You miss the old emails sometimes but it's worth it.
I think it's possible we'll learn more soon about who hired our hackers, which is exciting! It was almost certainly a major American ISP, or the lobbying umbrella group they created. It's my optimistic read that blowback from this case has already eroded the practice of dirty tricks like these. More lobbyists and companies getting caught would strengthen the effect.
Since I left Fight for the Future I've been working on a Signal alternative that feels more like Slack, for teams facing similar threats. Hopefully something comes of that too!