From the article, it sounds like they just looked at old incident reports and said "yup, these two are 'sophisticated,' they could be the NSA/GCHQ."
Its a little disturbing that the "sophisticated" attacks they detected don't really sound all that sophisticated. Is spoofing an email and sending a PDF/Office exploit really considered sophisticated? While its a step above the most basic script-kiddie type stuff, that isn't unreasonable for even normal pentesting to do, and I wouldn't consider it an indicator of a nation-state attacker at all. Even if the attack was using 0-day in the attachment viewer, its not unheard of for malware kits to employ similar techniques.
It definitely says something that those attacks were at least partially successful against systems Gemalto thinks could have resulted in the theft of sensitive crypto keys.