So I have some experience in this.
I agree that negligence, recklessness, knowledge, and purpose are different mens rea standards. I don't think that gets us to your conclusion, though.
“Deliberate intent” isn't a freestanding CFAA element requiring someone to have a mental picture of the completed hack and affirmatively desire that exact result.
The relevant question is the mens rea attached to the particular CFAA provision. For unauthorized-access cases, that can include whether the defendant knowingly accessed a system and knew the facts making that access unauthorized.
And knowledge is not limited to an admission or even necessarily positive knowledge. The OPs usage of Nosal is on point here: the Ninth Circuit upheld a deliberate-ignorance instruction under which knowledge could be found where the defendant was aware of a high probability of unauthorized access and deliberately avoided learning the truth.
So, if I'm reading this right, and I think I am, the OP is not arguing that negligence or recklessness automatically becomes intent. He's arguing that repeated unauthorized outcomes, notice of those outcomes, and subsequent conduct can be evidence on whether the actual statutory knowledge or intent requirement is satisfied. I agree with this assessment.
So “nobody wanted random websites hacked” may be factually true, but it doesn't by itself resolve the CFAA mens rea question.