To an automated protection system that detects “repo deletion + index.html rant” commits, deleting the codebase and updating the README would red flag instantly except for the different filename, and catch lots of garden-variety intrusions.
The deletion here was more complex, and most likely a human was assigned to review user reports to GitHub Security, who accurately determined it was a defacement from someone claiming to be the author’s credentials.
Turns out the author was the attacker, and with that confirmed, it appears that their access was restored so they could proceed with it.