It's good that this was published, some tough lessons in there. It's missing a timeline though, which is important to learn from - when was it realised that user data was accessed, how long did it take to figure out that keys were stolen, exactly when & what actions were taken to protect customer information, etc.
Other interesting details not covered was whether an incident response plan existed or was followed, how many unpatched Internet-facing servers were sitting around and whether any existing security measures did actually work in slowing down the attacker.