IIRC the fishing link used for the hack pointed to a mainstream URL shortener; and the account that owned that shortened URL used in the fishing op was associated with other URLs dating years back used for fishing campaigns against russian journalists and dissidents.
Hence, pretty strong reasons to suspect Russian state involvment.
I was thinking about another case around the same time where a DNC member had his gmail account compromised by a spearfishing attack (which IIUC is also different from the "DNC leak"). The broad strokes are similar though.