Even though the company didn’t really do anything truly wrong in this case, as it’s simply users reusing passwords, they still should have been better/more proactive especially with such sensitive information
There's nothing special or new or unique or unforseen about the security requirements of 23andMe.
They absolutely failed to implement an appropriate level of security measures for their service.
Mandatory 2FA could've prevented this.
Hence the key word: mandatory.