I don't get the ransom thing: users of a git repository have a clone of the repo that contains the whole history, no? So isn't it trivial to recreate the repository?
The attacker is also threatening to make these private repos public, or misuse their access to the repos in other ways (likely additional types of breaches).
I do not have local clones of my old projects.
For some repositories the code may be of little concern if the hacker shares it with the world or deletes it.... but it could impact some users.