The author probably meant if the site gets/is hacked, or if they are later bought by another company, or if a new employee joins and you can see chat history... etc.
And their ad networks might well be infected with malware. But because of deep packet inspection and editing, you can't tell that the malvertising in question actually came from AT&T or Spectrum instead of Gmail.
I'm sure Google would not be happy with content injection into gmail.
It's similar to the old adage about driving: "Drive like everyone else is an idiot out to kill you. Don't be right, be predictable."
Edit: In the worst-case, as per the GP's point.
The difference is that if I own the server, I can see your information even though it was a direct server connection. You directly fed the information to me. That is what is happening in these scenerios.
And plenty of ISPs will do exactly that, if you give them half a chance.