Not technically advanced to understand you!
What he was suggesting was that someone managed to generate the same address as you. Not only is the probability infinitesimal, but given that you've also lost NXT and assuming they were both on the DB account then it would obviously point to DB as the attack vector.
Dropbox is an assumption. He had a plaintext file with all his passwords in it. He used Electrum, so I assume he has the seed stored in that file too.