I think that not all companies are the same.
Some companies put a lot of effort in security (Apple, Google, Facebook, etc). Usually they have engineering driven cultures.
The other majority of companies see security just as a cost center that needs to be covered in order to reduce legal liabilities.
The second kind of companies do not have a bug bounty programs because they know that they have too many holes and prefer not to attract too much interest.
For those companies that may have huge capitalization and profits, paying $1M for a vulnerability is not practical.
I expect that in general all companies (including those in the first group) detect compromised accounts and services from time to time but unless they have to disclosed because the laws demand it, they prefer to avoid the bad PR and potential lawsuits.
But while I expect the first kind of companies doing a root cause analysis and improving the systems, the companies in the second group of companies usually just clean up the detected compromised systems and avoid to look too much deep because either they do not have the skills or they are afraid to find things they will have to disclose and be liable for.