Yes I completely agree. In the local news there was focus on which company it was and that the password was 123456.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
The older the system, the higher the chance it never got a proper security audit, and/or it was built with a lot of implied trust, like most old Internet standards are.
As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).