I would be extremely surprised if a state-actor like China couldn’t access most US company data at will. If you can invest several billions and have thousands of people working to create a breach, no company is safe, not even AWS or Microsoft. In this case, that’s even way easier, the company is Chinese, the CCP can have this access lawfully, is this something unexpected? I’m much more concerned by the laziness of mo…
Having information available for easy perusal via a commercial channel (which is potentially not even illegal) is very different from having information accessible via use of national-asset intelligence capabilities. Information which can only be obtained the second way is almost certainly going to receive different treatment than the first.
There is value in making information more difficult (and more illegal, and less socially and politically acceptable) to access, even if that control is not 100% effective or if there are still ways of getting around it.
Increasing the friction involved in accessing personal information is an imperfect win, but a win nonetheless.
For most users of commercial software, your system is penetrable and should be considered insecure against a nation-state level attacker willing to spend a 0-day on getting in. But that doesn't mean you should just leave everything hanging out in the open where any doofus can get to it, or voluntarily hand your information over to an unfriendly government's partner corporation. At least make them work for it.