It's suspected that computer forensics managed to recover the private key of an unencrypted wallet from his disk. The sequence of events would be: He previously used an unencrypted wallet. Then he encrypted it and deleted his old wallet.dat. Then he forgot to zero out his "deleted files" area of his filesystem, so the old wallet.dat was recoverable via forensics.