GitHub suffered a third-party breach after a malicious threat actor was discovered smuggling data out of the repository using stolen OAuth tokens.
https://www.securitymagazine.com/articles/97458-github-notifies-organizations-of-third-party-oauth-token-theft