I agree, by all accounts 23andMe didn't do anything wrong, however could they have done more?
For example the 14,000 compromised accounts.
- Did they all login from the same location?
- Did they all login around the same time?
- Did they exhibit strange login behavior like always logged in from California, suddenly logged in from Europe?
- Did these accounts, after logging in, perform actions that seemed automated?
- Did these accounts access more data than the average user?
In hindsight some of these questions might be easier to answer. It's possible a company with even better security could have detected and shutdown these compromised accounts before they collected the data of millions of accounts. It's also possible they did everything right.
A full investigation makes sense.