What's more, getting into one's backend servers/gaining some kind of access to DB, config files of the machine, etc. is, in my mind, just infinitely worse than gaining access to a computer of a person/uploading some ransomware/something similar.
We're just probably working with different SW, so we both see the thing that touches us the most as the problem... :))