It still suggests Gitlab's infrastructure (internally) was compromised: "Suspicious git activity detected on Gitlab"
Something like "Gitlab users' repos held for ransom" seems more appropriate.
No comments yet.