Doesn’t appear to have been hacked like all the hacks we hear about rather, the user probably reused their password on another service that was hacked and they didn’t change their passwords as hopefully instructed when that occurred. Enabling 2 factor would resolve this in most alll cases easily for the user. Versus the user having to use a password management app and constantly monitor their security and update accordingly. 1Password helps a lot but the average person won’t use that so it’s on companies like Apple to continue to improve their keychain software to help automate this for users and on companies like nest to push 2 factor more. But until Apple and other natively support 2 factor seamlessly it won’t gain massive traction for non tech users. So while this was the users fault technically it’s ultimately tech companies fault for not making security for users more fool proof. Though if everyone uses 2 factor hackers will probably find another way.