Earlier quoted context omitted.
I'm sorry, but in between your Straw Man argument and your indirect Ad Hominem attack, I fail to see you address the point that these kids caused harm to a business. Nowhere did I say that PHPFog bears no responsibility for the security of their service, but that doesn't excuse what these kids did one bit. I'm just much more impressed with the way that PHPFog is handling their business after the fact than these kids…
>I fail to see you address the point that these kids caused harm to a business Very well. These kids caused harm to a business. So what's that change? The business screwed up, badly. The agent of destruction is quite irrelevant. Had it been a power failure, backup failure, permissions failure, data leak, or data corruption would PHPFog deserve any less blame? This need to shift some responsibility to a bunch of kids…
They aren't shifting responsibility. The kids are responsible for their own actions. They did something illegal. They are responsible for it.
Now, PHPFog is also responsible for protecting their customers; they are supposed to provide a secure hosting environment. PHPFog is a victim here, but has also acted irresponsibly with regards to security (not criminally irresponsibly, but if harm did come to their customers due to this, there could be possible civil liability). The fact that PHPFog bears some blame for their security practices doesn't take responsibility off the kids who broke in and vandalized their systems.