It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple.
When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in return. My hobby is security, my payment is knowing that I helped thousands of people out.
>I would NOT be happy to receive such an email.
You would rather just continue to expose your customer's information? Interesting... I don't think you have the ethical high ground here, if that is your position.
I'm not sure what you find ambiguous or confusing.
The breach that he actually did. They should fulfill their obligations under the law, and they should file a report with their national law enforcement agency with information about the person who is claiming to have done the crime in question.