Over 70% of successful attacks are coming from "inside". So by probability, they hired the wrong guy, regardless of the details.
This. Why would you spend millions and possibly years to try to decrypt the files if you can just use human factor and get away with a few grand admin's bonus?
Exactly.
Also, some admins hold personal unencrypted backups of encrypted data.
Social engineering is, not by accident, still the most popular "key" to the most widespread backdoor: the user.