It's not like your two options were either wipe the box or take over their twitter account.
A responsible pen-tester would have reported the issue privately and disclosed it publicly at a later date.
Take a look here for a protocol to follow in future http://www.wiretrip.net/rfp/policy.html