Presumably the attacker used Google's own LLM and they searched the history of all user chats to find the transcript.
I say this only slightly in jest, as that's about the only thing I can think of which would legitimately give them 'high confidence'.
In the article (AP one, at least) Google explicitly said it does not believe it was Gemini or Mythos.