1. He discovers an unprotected database.
2. He mails the CEO of the company.
3. The database is fixed.
4. He mails the CEO again to say he's publishing.
5. The CEO replies and says there was no security breach.
6. He goes spelunking in the database tables to write a rebuttal?
How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access to it in step 3?