I agree with other commenters that these data breaches have been happening for too many years and across too many industries, from the financial sector to retail to government. Penalties should be severe: fines, prison time, disgorgement, depending on the extent of the breach and the negligence behind it.