Mastercard should be heavily fined for this. And I mean really heavily, like some percentage, or fraction of a percentage of global revenue. That's how you get them to take security seriously.
This means that at least in theory a security researcher could work as a contractor at a competing firm to then let their legal department send a cease and desist letter and demand recouperation of the legal fees including the money paid to the security researcher to find the vulnerability.
Anyone who quotes me on this in their court case is an idiot.