My own problem with the top-level comment wasn't that it claimed fault on the part of the victims, it's that it didn't substantiate why that claim of fault was applicable in this case.
Multiple use of weak passwords in a critical system isn't acceptable in 2026 (nor has it been for many decades), and yet there's credible evidence (as my own follow-ups in this subthread and my own top-level comments should indicate) that the victims here did contribute significantly to their own harm. For that they should be found accountable. Hosting inherently insecure data systems is gross negligence, quite arguably criminal.
If so, point to references. Otherwise your original comment reads as unsubstantive. Tropes and cliches may have value because they're often true, but if true, in this case, then share that fact and not the trope alone.
and click on the links in the article - they are screenshots from inside the system.
Like this one for example: https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...
To answer your question: yes, in this specific case, documented.
Your initial comment would have been far more substantial, and probably much better received, with these additions.
In an ideal world, even before you crash your motorcycle and hit your head somewhere, forcing you to start wearing it
Then a city bus passes them far too close. The passenger side mirror of the bus catches the rider's helmet and speeds off...carrying the cyclist off of their bike and dangling by their helmet at speed...
You should take a closer look at the screenshots posted by the hacker: entire systems and network devices with the password P@ssw0rd for the admin user. Now you tell me.
Take a closer look at the screenshots posted by the hacker: entire systems and network devices with the password P@ssw0rd for the admin user.
Linking those would be bonus.
<https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...>