"We knew the attack was serious enough to completely shut down our service, but not serious enough to warn people of a potential identity theft situation."

Um, yeah. Not buying it. The real answer is that they suspected as much as soon as they brought the service down, but were hoping they could prove that it wasn't true. Now that they've been getting bad press they come out and say that it's possible. Nothing but a PR-related decision.
_________________________
Bitt Faulk