What data was breached? If the answer is none, there is no GDPR action to be taken.
>Because the company kept a limited set of activity logs, it was unable to determine which users were affected and what types of data may potentially have been improperly collected, the two people briefed on the matter said. The bug existed since 2015, and it is unclear whether a larger number of users may have been affected over that time.
Reckless endangerment deals with the possibility of something bad happening, but notice that word "reckless."