I blame Sony as it was their responsibility to protect that data, and they failed. Certainly, it was the hackers who stole the data, but say for example someone steals the contents of your deposit box from a bank. Do you go after the theives? No. that's the job of law enforcement. What you do is go to the bank to get reimbursement for what you lost.
Is it the bank's fault they got robbed? No. Is their level of security relevant? Not especially. Even if they held your stuff in a bomb-proof vault with DNA scans and other state of the art security, they're still responsible for reimbursing you for what was lost.
True, we're dealing with data here, not physical objects, but I feel the analogy holds up.