@dko @dplattsf @pjohanneson @thomasfuchs
If they cared about security, they would have scanned their userbase cross referencing the emails on HIBP & forced an email change on them.

If they cared about their users data, they would have implemented MFA to minimise 'weakest link' vector.