For example , someone has a great idea for a site, picks up a basic PHP book, reads all of the "advice" on PHP.net and hacks it all together with a few copy and pastes from various coding forums.
Let's say they get some traction and pick up a few hundred users who start putting personal info in there , reusing their bank password and linking it to all of their social media accounts.
Problem is that the app is a mess of md5 or plaintext passwords and unsanitised input and when that thing gets owned by some hacker it can have real consequences to those users who trusted it.
This might be slightly hypocritical though, since this is basically how I learned to code in my early days but now people have so much of their life online that the stakes are a little higher.