Apple use a centralised credential system. If I was to speculate I would assume what's happened here is the metadata attached to the developer portal (developer contact information, company info, etc) was compromised, not the actual Apple ID. This would explain why Apple are saying no 'sensitive' information (passwords?) was taken.
Good scary point (I don't). At least I've pre-emptively disabled Find my Mac to avoid another Wired-like remote wipe. Imagine that being pushed to all ios and mac developers at once!