Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to extort money from a company by dangling a dump of their customer database.
Hacked a site?
Send them a message about it, give them time to respond and time to fix. If they don't respond after a reasonable time has passed go public with it, don't try to translate it in to paid work.
It would be good if more companies set up bug bounties, and even better if they'd set the reward a bit closer to (reputed) black-market prices.
[edited to fix name. sorry 'bout that, been a long day]
> Extortion, outwresting, and/or exaction is a criminal offense which occurs when a person unlawfully obtains either money, property or services from a person(s), entity, or institution, through coercion.
Where is the coercion? Is there a threat here to do something? I can't see it. In fact, the opposite - the damage is already done.
The coercion would exist only if there was a threat to do something bad from the extorter, which really, I can't see at all.