My guess? They worked with the CEO to discuss the issue. Then recommended hiring some consulting company that specializes in key management. The consultant says something like, you need to keep a copy of the keys in an offsite vault for disaster recover purposes. The NSA now has the keys.
It is also possible they just got the keys from spies. In my company, anyone with sudo access to front end machines can get the keys. I have no idea how to keep these keys secure from the NSA.