I would say that part of the "escape" stories is probably just absolutely pathetic human incompetence at work. I mean, not checking signatures on access tokens? It does not get more abysmally incompetent and entirely without even basic understanding than that. Sandbox breakout is also a thing we _know_ how to prevent when we can restrict what the thing inside the sandbox can do. And monitoring whether some software is accessing the Internet? That is network monitoring 101, first week. You have to actively not do it to even be able to mess it up.
That said, we definitely have either gross criminal-level negligence and incompetence or intent in these "breakouts". We may have both. The business numbers of the LLM pushers are so abysmally and catastrophically bad, they would have found themselves in bankruptcy court years ago if they had a different product. They absolutely must keep the hype going or they are dead. So some or a lot of intent behind these "breakout" stories is more than just plausible. Overall, this cannot be a good thing and they show exceptionally bad things about the LLM makers, however the actual facts really turn out to be. These are not people you would want to give data of any value and you most certainly do not want them to have your trade-secrets, your strategies, your code or your private thoughts.