The real reason your scenario is unlikely is just that Exxon practically owns the government, so they would change the laws or something to fuck you over.
But I mean what if you discovered a security vulnerability at McDonalds or something, a way to pick their locks. Why are you morally obligated to disclose it without compensation?
On which moral principle are you condemning them?
If you send a letter to a bank saying "I have found a breach in the kind of vault you use at your banks, I'm giving the details to some expert robbers but you can't have it unless you pay me $10m", with evidence you've done it, I'm pretty sure you will find yourself waking up at gunpoint at 6am, courtesy of the FBI.
Since unauthorised access of a computer is a crime in many places, I'm sure you can see the relevance, even if the consequences aren't as drastic. One hopes that we have misinterpreted this and that they have performed 'responsible disclosure' by telling Google all the details.
I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be crossing a line if they posted a press release trumpeting a major vulnerability they discovered, mentioning by name which company and approximately where the vulnerability was located, but then refused to disclose it to the company in question.
I'm not sure how much it survives, but I believe there was traditionally even a common-law "duty to warn" if you were aware of significant risks to someone's person or property.