I'm not sure they knowingly ignored best practices, it's probably more that they were ignorant to them. I've personally meet with Chaos (chief security officer) from fortune 50 companies who didn't have a clue what ACLs are, how encryption works, or what an onion security model is.
A lot of these people have been in the game long enough that many best practices we're invented after they stopped learning.
This is does not justify their behavior, rather it provides more context around the a potential contributing cause.