Earlier quoted context omitted.
Why would they try to identify you from your "behavioural patterns", when they already have the device identifier and your Apple ID, which identify you are your computer uniquely? Which, to be very specific, they _do not send_. They COULD identify you extremely easily, and they specifically chose not to do that.
May be they have other channels which could or already do send device identifiter and Apple ID. How do you know what _else_ they do ? Who knew they were sending hashes till the recent malfunctioning? What _esle_ we do not know now?
And it was known this data was being sent.