Fair enough.
Moving forward with my assertion and based on what others are saying about the Apple testing practices; I'm guessing that this was something that Apple should have caught in their testing, which if true would go towards proving culpability.
Negligence would then be the argument I'm guessing and then liability would follow.
I understand from many other situations it's arguable about whether the company could have foreseen the issue.
Typical breaches like the Dropbox breach which passwords were still hashed and therefore the request to reset the password was proactive. That's an acceptable breach to me and is bound to happen, but negligence such as Apple's or in the case of BA (British Airlines) breaking with known and valid credit card processes should result in conseuqences up to the criminal level depending on the situation.
BA link: “So, about that BA hack …” https://medium.com/the-automator/so-about-that-ba-hack-a82e5...