More effective, perhaps, but it's also dancing on the edge of the law. In the Netherlands the public prosecutor doesn't pursue cases of ethical hacking (afaik the other party can still file a civil case if there are damages though, and I would assume reputational damage counts), but they totally made a case against a person that claimed to be white hat but offered to fix the problem for around 20'000 euros. Specifically:
> De man nam contact op met de praktijk en meldde dat een kwetsbaarheid toegang bood tot de persoonlijke gegevens van artsen, waaronder e-mailadressen, gebruikersnamen, wachtwoorden en bankrekeningnummers. Vervolgens stuurde hij een offerte met het aanbod om voor 16.500 tot 23.000 euro de kwetsbaarheid te verhelpen. In die offerte stond volgens het OM een 'dreigende mededeling': "Er zal waarschijnlijk een boete betaald moeten worden wanneer dit openbaar is en er zal een flinke reputatieschade plaatsvinden." Het OM schrijft dat de politie na onderzoek constateerde dat op de laptop van de man de gevoelige persoonsgegevens stonden en dat zijn ip-adres te relateren was aan de inbraak.
From https://tweakers.net/nieuws/167792/om-eist-twee-maanden-cel-...
Summary translation: he found an issue in a doctor's office, told them "you'll probably get fined if this becomes public and there will be large reputational damage" and sent an offer for 16.5-23k euros for a fix. The public prosecutor saw the message as threatening (blackmail) and therefore decided this wasn't simply a white hat reporting an issue and offering legitimate services. Upon investigating, sensitive personal data was found on his laptop.
So is hacking into their printers to send a message proportional to the issue? I would say yes, but one might also argue this goes beyond what is strictly necessary to prove the issue. (Another guideline is that downloading your own PII to confirm an issue is fine, and that it can also be fine if you accidentally find PII but don't request more than that first record, but nothing beyond that.) You might argue that they didn't listen, but I don't know if that's an argument a judge finds compelling.
Different countries can have different systems, not sure how white hat hacking is treated in Iran, the USA, Brazil, or other countries that seem to enjoy putting a lot of citizens behind bars.