Earlier quoted context omitted.
Companies have a reasonable obligation to protect our data, so I'm with you if they were negligent in prevention, detection, mitigation, or revelation. If they took reasonable measures to prevent, and were forthcoming if compromised anyway, and took measures to minimize damage to users, there's no reason to blame them.
It's OUR data, and WE as individuals are the ones who have to clean up the mess after aggregators spill it. Perfect security is impossible, but let's not forget 1) who is harmed, or 2) who is getting rich and who will in a worst case will cut their losses, go bankrupt, then start another company with the accumulated weath.
So the real issue should be: When and how will a new secure form of identity be created, used, and made available. Social security numbers were never intended to be used in the manner in which they are.