That would require mens rea. This may be criminal negligence, but it wouldn't be more than that. (I am basically 100% sure none of the employees or execs are intending or desiring any of these outcomes, regardless of the very large number of people who believe in conspiracy theories about regulatory capture and other sinister motives.)
I'm totally on board with treating it as gross negligence requiring hundreds of millions or billions of dollars paid in fines and compensation to victims, but don't act like this is more than what it is.
The CFAA's main hacking charge has a high bar for intent. But the CFAA also has a separate "damaging a protected computer" charge (basically to criminalize DOS attacks) and that charge only requires negligence not specific intent.