Compartmentalization is one of the strongest defense tools we have. For example, with the icloud leaks an attacker was able to gain access to all the data in a single strike. If it's true that Apple can no longer decrypt user's icloud data, an attacker now needs to hack people one-by-one. Hacking takes time and effort, and a one-by-one payoff may make it that hacking icloud is no longer worth the effort. Users are safer, even though they are still theoretically vulnerable.
A lot of people are stepping up to the plate to offer stronger security on digital systems. (Qubes, for example. Let's Encrypt, for example). If choose to take security seriously, hacking will become harder, the rewards will plummet, and the world will be safer.
...security will become less of a concern, hacking will become easier, the rewards will rise, security will be taken more seriously...
There was an issue with allowing brute force attacks which was fixed. But all the publicised hacks were to do with individual accounts being compromised.
I think in one case the "secret questions" used to reset accounts was actually asked during a media junket by a fake reporter.
No, they likely wouldn't fire someone unless they specifically had controls in place for that (eg. security clearance area). People "tailgate" at companies all the time.
http://www.pacifict.com/Story/
In addition, the "value" of these records shot up dramatically once Russia was banned. The security was not stepped up to match.
The real problem is the fact that managers DO request passwords, access control changes, etc. via email, and they do it more often than people get phished. So, people learn to give out information rather than protect it.
I think a more constructive reaction would be to say that phishing training is important and should be implemented or revised. In addition technical solutions should be investigated. Perhaps some of the infallible people who never fall for phishing attacks can automate part of their brilliance for the mere mortals.