We won't get any technical details. The fact that this was pulled off and the initial compromise was a year ago means they've got no alarm bells for someone dumping the DB.
It's negligence at it's finest. Here's to hoping for class-action. 2 years free "identity theft protection" (which is useless to consumers until post-theft) and credit-report monitoring (which is free to them, and again only comes up post-theft) is pretty bullsh*t.
Roll some heads and hand out fines.