Earlier quoted context omitted.
They admitted that the encrypted CC numbers were leaked, they didn't mention if the encryption keys were stored on the same machine. The alleged hacker said that the encryption keys were stored on the same machine, making the encryption useless.
It was also made clear that the encryption key was protected by a passphrase which was not stored on the machine.
I am sorry, them confirming this fact, and even if I recall adding a smiley in the tweet they did it, just cemented that they do not understand their business.
They clearly wish to give the impression that they are "secure". They need more lock icons...they are almost as effective as the racing stickers on my car!