What is the source on the SSL keys? Arguably a lot of metadata could be gleaned without even decrypting the data. If an IP is tied to an identity, timing of traffic alone would be very revealing.
It is also possible they just got the keys from spies. In my company, anyone with sudo access to front end machines can get the keys. I have no idea how to keep these keys secure from the NSA.
[1] http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se...