It would be interesting to ascertain how many times users' on social media flag a security problem to a company's social media team that isn't actually a security problem? In other words, how many false negatives get caught too?
Troy Hunt's post is really told from the victor's perspective (likely a bias rather than intentional or arrogance), but to form a well-rounded view, understanding how many false negatives would likely help...