That said, I'm a bit surprised to see a "Rake them over the coals" attitude on HN. They leaked a DB with hashed passwords, user data, and last 4 digits of credit cards. That happens to even the most responsible websites all the time, even with seven years of best practices to build upon. I know it would have absolutely happened to the awful, framework-less PHP I was writing back in 2012.
Without letting Zappos off the hook for not taking security more seriously, it seems to me that substantial, non-ridiculous monetary punishments should be reserved for instances of deliberate recklessness, or at least clear, preventable negligence.