Unfortunately, neither Radiant nor resellers are responsible. It is the owner who is responsible for maintaining their own data security. The only thing Radiant or resellers can do is ensure that they are using PA-DSS compliant software. Radiant and resellers can advise and consult but cannot force someone to maintain data security. Sadly, restaurateurs are always looking for the cheapest way to do business and don't always listen to best practices. Plus, they need to be the ones keeping up to date with their security scans and SAQs. These are implemented by payment services or other third parties. PCI and CISP encompasses much more than just the software.
How wide spread was it? Ask the Russians.