You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.
Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible
That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize