1. Tell your client to immediately switch to another service provider for his online store. When the current one gets hacked (note I said
when, not
if), your client's customers aren't going to care that it was a third party provider your client was using. They will look at it as they trusted your client and that trust was betrayed.
2. Perhaps an anonymous tip to Visa and Mastercard would be in order. The provider needs to be shut down, as what they are doing goes beyond any excusable security failure. Almost every developer, no matter how good, can botch security--and so if all they were leaking was credit card numbers, names, addresses, and phone number, it would be at least remotely forgivable, if they were to promptly fix it.
However, you said they have the CVV too. That is not supposed to be stored at all. Of course, an online store site has to keep it for the duration of processing the transaction, but that should only be a few minutes. The fact that they are storing CVV shows that they are beyond redemption.
3. As for the numbers and other data you downloaded, secure delete it. I doubt anyone is going to care much about it. I once had a file with about the same number of card numbers and contact information, which I received unsolicited, offered up as a sample of the 100k cards the sender wanted to sell me. I was able to do some checking and determine that the information was apparently legit.
I called Visa and (I think) American Express. I naively thought they would be interested in putting immediate holds on the accounts. Nope. The FBI was not interested either--they suggested that the Secret Service would be the appropriate agency to deal with someone trafficking in stolen credit cards. The Secret Service disagreed. Eventually the next day I found someone at Visa who asked me to mail her the list.