You're the one that connected an impossible-to-security-update device to the internet. You can do plenty of home automation without it needing to be that way, if you're open to a little more setup being involved in the process.
I have no idea of all the details, but in legal terms this is called "res ipsa loquitur" -- in this case, the fact that it clearly seems compromised is pretty solid evidence that it wasn't immune to compromise.