No need to look for malicious intentions, this is just a feature that costs money so it's very low (or zero) priority for profit driven organisations.
I wonder if finding people responsible and spamming then with their own service emails would make the team care enough to fix this. But of course that's mostly dubious, probably illegal, and shouldn't be a responsibility of some vigilante hacker