Squarespace is directly responsible, my irrational instinct is to blame Google even more, in that their role involved active abdication of responsibility for purely self-interested reasons and involved more employees than just their security engineering team.
Domains are critical infrastructure, wasn't any reason to sell them other than Wall Street puffery. Obvious downside was leaving business customers who got them via Cloud exposed. Per my uninformed intuition at the time, there wasn't a secure way to do this sort of switchover without a lot of manual reaching out neither of them were going to do.
Additionally, Google went out of their way to sweeten the deal by A) making Squarespace the reseller for any associated Google Workspace records which B) greatly widened the vulnerability surface. [1]
This sounded uninformed to me, until it happened, so [2] quotes the retrospective at length to show there was no secure and automated choice.
both via Security Alliance's "A Squarespace Retrospective": https://securityalliance.notion.site/A-Squarespace-Retrospec...
[1] "Furthermore, as Squarespace is an authorized Google Workspace reseller, any teams who had purchased Google Workspace through Google Domains had their license transferred to Squarespace. This allows the threat actor to create new administrators in Google Workspace via the hijacked Squarespace account."
[2] "However, what happens for [domain owner] emails which are not already registered to an [Squarespace] account? Well, you could preemptively create a new account for that email and send them a temporary password, but sending passwords in plain text is not a good practice, it would be pretty complicated to create millions of users with temporary passwords, and most people migrating probably want to use their Google account to sign in, not a password. Maybe your systems don’t even support creating temporary users like this."