NSA = Cryptography and surveillance. This was most likely an FBI raid, or CIA raid. The servers that were infected were TorMail and that one Tor web host, I forget what it's called. The sites both read "Server down for maintenance" when it happened, and it utilized a JavaScript vulnerability in the old Firefox 17 to send a cookie to an IP address most likely controlled by the government that contained your real IP and some other information about your computer. It was meant to de-mask the Tor users, giving their real IPs to the government.
If you have the Tor Browser Bundle, make sure that your NoScript is set to "Disable Scripts Globally". For some stupid reason this doesn't come as the default.
This vulnerability only impacted users of the older Tor browser bundle, as the latest one is upgraded past Firefox 17.
To tell the truth, there's not much t

rry about unless you deal big-time in fraud. Eg. if you do carding, money counterfeiting, or any of those things on the deep web. This attack was most likely aimed at those who things, along with child pornography, but soon they may be migrating to attacking the hackers of the deep web also.
If you would like a full report of the reverse engineering of the payload and exploit, PM me and I'll send you the link to the Reddit post on /r/ReverseEngineering, I'm too lazy to find it right now.