No. They don't care if customers get pwnd. They care if customers become aware of exactly how they got pwnd and launch a class action. It's shitty but entirely predictable behavior common in these situations.
“force rotation of all customer credentials” = make customers change their passwords, which is a huge red flag that would draw attention to why they were forcing that.
Github just recently logged out all users because they had a bug that could leak other account data into sessions. They were very transparent about why they did that, what happened, and I for one trust them more for it.