It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.

Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.

It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.

It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.

Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.