I think the criteria of reporting should be something along the lines of "If the data that was stolen is the user's, then report to the user". If it can't be determined what was stolen, just report to everyone. This should be an embarrassing situation for the company.