As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done. Some of these expenditure campaigns are low-visibility, some even to the employees of the company, and they are usually not very sexy or noteworthy, so you won't read about them on the front page of CNN but they do happen and they are very costly to the company (in the ballparks of tens to hundreds of millions of dollars).
I do think there should be harsher punishments in the form of fines, etc. But to say that there is "zero impact" just isn't true.