The old “It wasn’t us, it was a 3rd party service provider” excuse doesn’t fly anymore.
Companies are responsible for vetting those with whom they share data or rely upon for critical services.
We audit about 30 per year on security.
IOW, they made updates and secured their system in April but failed to secure anything prior to that.
My sister had her account at her bank hacked a few months ago. DoorDash was on the list the thieves used.