Do you mean "any company that accepts credit cards" or "banks that issue cards"? In the first case, they care about security because breaches like this get them in hot shit with the banks. And the banks care because they have to refund the fraudulent charges. They probably don't care too much about your privacy, but they definitely would prefer to keep credit card numbers safe.
Also, the usage of firewall is totally appropriate. The firewall kept the bad guys from connecting directly to the database, so they had to bypass/penetrate via the webapp.