I suppose the Estonians are partially at fault for trusting Gemalto with anything, post Snowden.
That's a hardware design error. The claim is that Gemalto failed to fullfil the contractual clauses about quickly informing the customer (the Estonian state) of the security breach, not the existance of the security breach itself.
https://www.wired.com/2015/02/gemalto-confirms-hacked-insist...