There's nothing really here about what happened or how they have mitigated it. Perhaps it's too early and they don't really know, but then isn't going back live fairly risky?
Aside from a persistent firmware threat, which has nothing to do with the attack vector, I don't see why "yay we're on AWS now" is any different unless they know the compromise was due to a specific piece of infra which is no longer present. Isn't it much more likely to be a bug in their software logic which would certainly not be fixed by restoring a backup...