It's incredibly unlikely that the attackers just so happened to have a cbmhost users key on them. There are 2 scenarios that are tens of times more likely:
1. They only had a part of a key, and were not able to recover the rest because they didn't have the rest of the key.
2. They used an alternative method of extracting characters from the keydat, which didn't succeed in extracting all the characters. Not wishing to show that there were characters mising, the attackers only took a picture of the characters they had at the very end.