All of those data breaches that happen every day are still completely unacceptable and 100% the fault of the company in charge of the data. Yes, it would be nice if all end users understood best practices, but the fact of the matter is, many will always be less tech savvy than others and that's partly why regulations are so important. Data operators have a duty of care. Unfortunately, time and again, we find that many weren't taking that duty seriously enough. Rarely do we get an unfiltered, completely truthful explanation for data breaches because it's in the data operator's interests to present a perspective that shows them in the best possible light. Only when a regulator investigates (because a breach was particularly damaging) do we usually get the truth, and it's almost always more disturbing than the original explanation.