23andMe's blame is an obfuscation of the problems which underlie this situation.
1. There is the matter of having insufficient granularity in their sharing options within the DNA Relatives program. It comes with two general levels, which is not enough.
2. 23andMe limits one to seeing the closest 1500 matches who have opted-in to DNA Relatives. That would have allowed a hacker to collect data on most people in the database despite having only a few thousand compromised accounts. (Haplogroups, ethnic origins predictions, names, profile data, a list of relatives, and information on geographic origins.)
3. The 1500 match limit would be helpful, in theory, however for some time (recently) it was possible to see profiles beyond those 1500 matches. I'm not certain if these were limited to only those who shared matching DNA segments but who fell outside of the 1500 match limit. And I can't be certain if this was part of the method exploited by these malicious actors.