No tinfoil needed for the explanation: they're pretty fat targets with code security at the level of normal startups.
It would be interesting to see how much they get targetted in comparison to startups that can at most spill some personal user info and cc numbers.