People need to stop with the 'sophisticated attack" shenanigans. No one is going to say 'un-sophisticated attack", when the reality of it is, it usually boils down to negligence. My bet is on an insider.
Interesting in this case is that the CTO / Co-Founder's son was previously arrested for creating the "Mariposa" bot net and money laundering.
https://krebsonsecurity.com/tag/matjaz-skorjanc/
http://www.bbc.com/news/technology-25506016