In my opinion, the fault is 90% at Apple for having horrible security practices, and 10% on the victims for blindly trusting in Apple..
Why on earth did Apple decide to not make any anti brute-force measures/warnings on their iCloud system? Did they even make any kind of security audit? I'm...