There's victim-blaming, and there's gross incompetence.
My own problem with the top-level comment wasn't that it claimed fault on the part of the victims, it's that it didn't substantiate why that claim of fault was applicable in this case.
Multiple use of weak passwords in a critical system isn't acceptable in 2026 (nor has it been for many decades), and yet there's credible evidence (as my own follow-ups in this subthread and my own top-level comments should indicate) that the victims here did contribute significantly to their own harm. For that they should be found accountable. Hosting inherently insecure data systems is gross negligence, quite arguably criminal.