Putting a password and emailing the admin would solve the password problem.
But I agree doing anything is probably illegal. I would leave it... not worth hassle of wearing the superman cape.
Emails have a bunch of info in the headers, so there is more meta-data in the email it self.
Neither is perfect for finding the culprit but one scenario has zero meta-data and the other has some.
That still doesn't justify vandalism.
They secured it, and somehow managed to make it publicly accessible again without password, this time it got hit by this attack.
Honestly this is like if a company decides to keep their paper records with my information on a public side walk, and somebody saw that and decided to bring them to the landfill.
Is it legal or fair? In a perfect world no, but at this point the company is not blameless.