I imagine its more of a precaution, I know I've worked on closed commercial projects where the commit history is sprinkled with business rationales for changes, and even the occasional grumpy word said about specific clients. Given they're doing this while winding down the company they may just not have time to audit every commit in a large project for sensitive information.
We hard coded some dev API keys, like email. We also had some customer names which we can't disclose committed in the early days of the repo.