Twenty _thousand_ people had their personal data stolen, many of them relied on these accounts to run their business, many put at risk of hackers impersonating them.
It only worked for accounts that didn't have 2FA switched on. If your livelihood depends on your account and you're risking not turning on some pretty basic security features then you should accept partial responsibility.
Did they partially hack their accounts? No, why would you be saying its partially the victim's fault when the billion dollar corporation doesn't secure their shit?