Any time a SaaS gets compromised there's a similar comment here about how
obviously this is going to happen when you give someone else your data, and it should have just all been within your own firewall, unexposed directly to the Internet.
I mean right this minute there's a privacy-focused SaaS on the front page for not being as private as everyone thinks. There's also a network hardware vendor on the front page for including back doors. A philosophy like "SaaS vendors know they can't allow security breaches" is really glossing over the need for layers of security and knowing that it's ultimately all on the trustworthiness of specifically who is involved.