The EU is actually already quite equipped to counter such behavior, with GDPR and CRA (Cyber Resilience Act) regulation they can not only penalize on consumer privacy protection (GDPR) but also on inadequate security practice (CRA), both allow either an absolute fine or a percentage of the annual company revenue.
I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...