Interesting that none of the talk around this has touched on any form of enforcement, even though this is illegal activity in US/EU.
Any fine would be peanuts for them but it might help to refocus the mindset from "oops, misconfiguration" to "test security but do so with care, consent and in line with the law"