> After reporting the vulnerability, the affected system was patched within 24 hours and never exploited maliciously.
How did they verify the never exploited maliciously part?
Did the person who's password they changed ever notice that their password didn't work any more and report the problem?