The question is, why should they care at all? Will this hurt their business?
Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.
Feels like their purpose is to test the boundaries, take the hits, and eventually sell off
Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.
Any breach of security on a system like this is a big flashing red-alert to me.
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.