blaming the victim

The government is not the victim, the public are. The government is responsible for protecting the public from attackers. Asking the government to do their job is not blaming the victim.

Added to the fact that, if I recall correctly, according to US law it's a breach even if the data is publicly available but unintentionally.

Refer: Weev AT&T

Which is mad, really.

Absolutely.

It is, however, a glowing beacon of an example of law being designed to maintain the status quo and/or protect companies at the expense of individuals.

As someone else said, welcome to late stage capitalism.

I don't see why, and I've no idea what "late stage capitalism" is, other than people like to repeat the phrase.

Not yet, as they haven't given details out. If they were not following standard security practices, then absolutely.

And when the victim doesn't do reasonable actions to safeguard, yes, they are also partially responsible.

If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.

Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.