>> do you think there should be repercussion from a legal standpoint when it comes to the compromising of user data that a company didn't adequately protect.
No, I don't. If you make a "legal penalty to being hacked" you reduce incentives for companies to admit it happened.
Like in this case they might have had a hack. Or they might not. But perhaps someone decides its better to be safe than sorry. But then legal steps in - no, you can't do that, it implies illegal activity.
Then there's "adequate protection". According to what standard? On what time scale? Which court has juristriction? Are you happy for the standard to be written in Europe? But applied in the US? What about multi-nationals? Security is a process, not an event. There are best practices, not" standards" - and those best practices change all the time.
And you can adhere to all the best practices, but suffer a breach because of social engineering, or a malicious employee etc.
Hacking is a part of society. Use unique, long, strong passwords. Assume all accounts will be hacked. Trying to make companies criminally liable won't fix the problem.
Regarding civil claims - they're already liable in the sense that you can sue anyone for anything (in the US anyway). If you can show damages, and convince a jury, then you're golden.