It ****ess me off to hear this kind of stuff. They always wait till something happens before they take proper action.
Just like the RIAA website. It's common **** sense that the RIAA website will be a high profile site to attack but yet they leave it wide open to SQL Injection attack.
These people need to lock this **** down before it happens, not after. Locking it down after an attack means nothing as the attacker has aleady succeded.
The people that runs those places need to be fired and trained correctly.