At what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.
Then again, my experience may have left me a little jaded.
There's always this culture of taking shortcuts at the expense of security and quality.
That said, the situations I’ve head about were from affiliate ransomware attacks that didn’t make the news because the backup worked. It’s difficult to keep things secure from highly motivated internal bad actors. I’ve been told it’s an increasing trend but have not heard much about it publicly.
Inevitably quality suffers. Until customers start awarding business based on something other than the number at the bottom, this kind of thing will continue.