It’s an interesting view. In this case you are claiming the victims are bound to the creator/vendor of the software/service, not the hacker?
My issue is that software security is not taken seriously most of the time because features are more important than spending a little more time on code quality.
The hacker is not the one writing buggy software.