Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.
During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…
Having worked at several similar companies, I'm guessing it went like this:
"How much should bounty be? Is $5K good?"
"Wow, that's nothing. At least make it something meaningful like 25 grand."
"Yeah....that's gonna be tough. How about split the difference? $15K"
"Sure."