I'm reading this as an embarrassing security lapse in general security, so they misdirect by talking in depth about password hashing.
They note that they discovered the breach on 'Friday' so I imagine they have an ongoing Incident Response right now. They may not have or be ready to share this information at this time, and that's fine. They might be working with law enforcement, further hardening systems, and continuing to confirm their findings to date to ensure they've mitigated the full impacts.
What's important now is conveying how users are impacted and what steps they should take to protect themselves; hopefully the rest comes in time.
There's a balance between early notification and misstating the impact.
It really is a great post and they always have action items for their users to protect their security. I have really enjoyed using them and will continue to do so.