I hope they reconsider and I think you've got a good case that this was a very serious attack, second only to getting a remote shell -- and a good stepping stone to getting a remote shell if you weren't so ethical.
I think you're confusing the expected behavior of the product offerings. Every user gets their own VM for free. would you be similarly convinced an attack has happened if AWS gave you a remote shell to the instance you rented?
You can literally just ask Muse for a remote shell, it's happy to give you one! And why shouldn't it? This is about as critical as Amazon granting you SSH access to your own EC2 instance.