The private keys are still vulnerable when they existed on the servers. It would be possible for their servers to be unknowingly breached. Moving the private keys offline won't help if they've been maliciously copied. The thief could wait a while (months, year) before stealing the funds.