> I haven’t made any transaction with those card numbers, told anyone specifics on how to get them, nor took any kind of advantage of this data.
Well, he just did. With this sloppy (forgivable if naïve), curiosity driven approach, I wouldn't be surprised ongoing exploitation wasn't simply the result of not cleaning up the test rig. Did he at least clear this with his lawyer before posting? Given the 404, I'm thinking not. Sheesh...