Seriously?
SQL security is so 2000, I can't believe those sites would even be vulnerable to those attacks.
Careless and lack of time usually go hand in hand. There are always exceptions, but with a large majority of security stuff ups time could be a big culprit.There are a lot of careless, uneducated, and/or pressured(by management to build functional and fast without care for security) developers out there. A report of harvesting like this is of no surprise to me, and it certainly won't be the last time it happens.