If you have a large enough user base that people depend, for whatever personal, safety or security reasons, on your product, then I believe you have a positive obligation to those people to protect them from risks and failures they might never see or understand.
Not because anyone's dumb or incompetent, but because those threat actors make every effort to be invisible to their victims and impossible to understand to defenders.