What permissions did the leaked tokens have? If they had write access, then leaked personal data is the least of anyone's worries. The real concern is how close the hackers came to infiltrating the image source for virtually every modern microservices system. If you could put a malicious image in say alpine:latest for even a minute, there's no telling how many compromised images would have been built using the base i…
Maybe some day we'll get serious about reproducible builds, since reproducibility can serve as a layer of defense against such compromises.
Definitely wouldn't have helped prevent the compromise.