Earlier quoted context omitted.
Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.
The connections need to pass through the US just once in order to give the US a chance to attack it. Since they created the internet, they have field advantage. It's almost impossible not to use a US based provider, it goes as deep as ipv4 distribution.
Less than once if the US were, purely hypothetically, to have a well-funded foreign sigint operation that might cooperate with domestic law enforcement on priority issues.