Companies embracing password login should be blamed for sticky note thefts.
Companies embracing email 2FA should be blamed for email account theft.
I dont know if this holds up hey. We see this time and again. An entity that does not break the law, makes itself available to the law, and its customers get hit by a criminal entity that does not follow the law. Because we cant snap our fingers and demand the government make thieving criminals double or triple illegal, people reach for a largely innocent party and want to make their lives worse.
Take a deep deep breath and let it go. Theres no unharmful level of punishing the innocent on behalf of the guilty.
This is going to sound wild and crazy but the people swapping the sim should be blamed for the sim swapping attack. What? Blame the criminal? I know its a bold stance but its correct.