Their data was exposed by breaching a third party service. I'm not sure how investing more in security could have helped prevent this.
You could argue that they shouldn't be housing this data with Snowflake but then you could say the same about a service like Amazon S3.
At what point is a company able to rely on a third-party vs being expected to run it in-house?