In my opinion the entire privacy breach is a non-issue. Here is what I think happened:
Some engineer at Google found a bug in Google Plus that could be used to access private data. The issue was investigated by the security team. They find that no harm was done. Incidents like this happen somewhat regularly at any tech company. Normally nobody thinks twice about it or even thinks about disclosing it to the public.
However, Google wanted to shut down Google Plus and wanted to avoid a backslash like with Google Reader. They used this bug as a pretext. Before Google releases this blog post, the post gets leaked the WSJ. The WSJ then puts a spin on it that Google didn't expect, because the narrative fits well into the current news cycle.