I'm inclined to give them some benefit of the doubt. It seems like they could have found out on, say, tuesday, started investigating (post-intrusion analysis is very lengthy to do thoroughly) and the boss said "we need to release a statement by the end of the week, so find out what was taken and how users are affected."
They'll likely be doing forensics for months after this, so alerting the public a few days in to the investigation is actually pretty good.
What you should be concerned about is all of the companies who got owned in this campaign and will not be confessing. This is big, and a few more companies will admit it early, a few will sneak vague statements in their SEC disclosures, and a few will cover it up completely.
They'll likely be doing forensics for months after this, so alerting the public a few days in to the investigation is actually pretty good.
What you should be concerned about is all of the companies who got owned in this campaign and will not be confessing. This is big, and a few more companies will admit it early, a few will sneak vague statements in their SEC disclosures, and a few will cover it up completely.