Apparently it was known in November and they first started getting hacked in December. It was a malware email that the payload link loaded malware that defeated antivirus and then dug deeper.
http://www.itnews.com.au/News/253712,epsilon-breach-used-four-month-old-attack.aspx
http://it.slashdot.org/story/11/04/07/1341255/Epsilon-Breach-Used-Four-month-old-Attack
http://www.itnews.com.au/News/253712,epsilon-breach-used-four-month-old-attack.aspx
http://it.slashdot.org/story/11/04/07/1341255/Epsilon-Breach-Used-Four-month-old-Attack