[warning: autoplaying sound]
https://finance.yahoo.com/news/people-successfully-suing-equ...
[warning: autoplaying sound]
https://finance.yahoo.com/news/people-successfully-suing-equ...
> ...the judge noted that Equifax had a duty to safeguard information, failed to heed warnings from the Department of Homeland Security, and “willfully” violated the Fair Credit Reporting Act and state regulations.
IMO, ignoring government warnings and violating regulations is much different than failing to stand up to an attack.
I would be very resistant to making "being hacked" a crime - in almost all cases, the hackee is the victim of an attack. If you feel the need for legal action, we should increase our "anti-hacker" laws and enforcement.
We don't fine banks for being robbed. It's the robbers fault something bad happened, not the bank's.
EDIT: formatting
No, we don't fine banks for being robbed. However, if the bank had clearly insufficient security on their vault, was notified of this being a problem, and made zero efforts to fix the problem then yes they should be held liable.
The comparison seems specious - the customers of the bank don't lose their money when a bank is robbed. The security is for its own benefit.
Still, your point stands.