He said the original article, not The Register article:

"The web application was compromised six months ago, several server scripts were modified to encrypt data before inserting it into the database, and to decrypt after getting data from the database. A sort of “on-fly” patching invisible to web application users."

They do not change any existing settings/encryption keys, they changed the scripts driving the web application so that it encrypted data using their key (which the web application retrieved by HTTPS from the attackers server) before inserting/updating it and decrypted it on retrieval.

They then waited for that encrypted data to overwrite/roll into all the backups for 6 months before pulling the key on their server, preventing the compromised web application from decrypting the data until they pay up.

