Based on the Snowden files, it seems completely plausible that the US has the capability to determine the origin of the hack. Of course, we all know that having a Chinese IP is not proof of origin, but what about network flows? The NSA has sensors all over the world analyzing traffic. They even have a limited history they can query. What if they could determine the endpoint of the data and see that there was nothing connected to that endpoint at the same time, sending the same amount of traffic (using it as a proxy). You might think this would be extremely hard, since there is so much data on the net, but if they had some implants on some routers watching a particular hotspot, they could reasonably make the determination that the attack originated from fingers on a keyboard there.
And let's talk about implants. The NSA has installed malware in China, we can agree on that, right? So if they can see that a known Chinese dumpsite has the stolen data, it's pretty obvious that China was involved somehow. Maybe they have hard drive firmware that constantly scans drives for particular strings and when found, it calls home. Inside the stolen data files were some of those strings.
With all the money spent on the NSA's infrastructure and the stakes involved in agitating a powerful nation, it stands to reason that they have made proper attribution a high priority. These guys aren't just looking at source IPs in a pcap and calling it a day.