I assume it was password reuse from one of their engineers or something similar. If you could compromise GitHub itself there would probably be higher value targets (source code for upcoming AAA games, Coinbase, government organizations, etc.)
I mean 100k is a lot of money and there is no saying they didn't hit those guys also
> If you could compromise GitHub itself there would probably be higher value targets (source code for upcoming AAA games
I'm intrigued. Why would that be a higher-value target?
AAA games have budgets in the millions. Threatening full release would likely net you much more than a few hundred thousands, and without requiring any secondary attack.
Are many (any?) AAA studios using private Github repos for development?