They don't get paid for the accuracy of their public pronouncements, it's just a marketing tool to raise their profile. It doesn't prevent them from being competent and maintaining clients.
Also, most clients would be more than happy to have someone proclaim that the reason they got owned was because they were the target of spooky foreign state actors and not because they're bad at security. There's no money in downplaying the sophistication of an attack.