I don't know what happened here, but presumably they keep fairly detailed request logs. If they were notified of a security vulnerability like this, they would probably sweep logs for suspicious requests. This way they would become aware of all breaches using that vulnerability, but not until they found the vulnerability, which could be any amount of time after the breaches occurred.