Yes I completely agree. In the local news there was focus on which company it was and that the password was 123456.

Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.

Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.

The older the system, the higher the chance it never got a proper security audit, and/or it was built with a lot of implied trust, like most old Internet standards are.

As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).

That's not how auditing works as I have observed it. Either your stuff is critical, or not. And when it is then everything which touches data sees an audit and no password policy incl. Shared and weak credentials is the first thing that would have been spotted. I would assume they buried some stuff to deep in a hierarchy and 3rd service partners that this company in the end got no proper audit.

Maybe I'm missing the point but isn't the parent comment asking with the admin accounts had no 2FA?

Oh no! Cost! Friction! Better just half-ass it then.

We're talking about a country with 6 million inhabitants, of which a large number is old and/or barely computer-literate and/or barely actually literate. Or doesn't possess a smartphone at all and only uses government services from a public computer in a library.

Government services have to work in all these scenarios, simply because that is a right of the citizens.