The thing about OpSec is that most people don't think about it before they need it. And by that time it's too late. That may not apply here though, because it appears they were loose with OpSec until the very end.
As a poor kid who put themselves through college, I definitely sympathize with, and understand that, the price of text books and academic work is insane. I may or may not have even used the website or its analogues once or twice.
But at the end of the day, they had to know what they were doing. If you're doing ransomware/carding/etc. you don't target Russia or its friends. And if you're trying to get around copyright law, you don't operate within reach of the US government. These are things that anyone who has been around security for even a couple of months understands.
Do I think people should be grabbed from foreign countries over copyright? No. But if you're operating in that world, it's colossally stupid to not take OpSec seriously.