>If the tech community wants this standard to change when dealing with intellectual property, we need to articulate
why and get people on board, because it's certainly not the default in either our current culture or our current laws.
As others have pointed out, the difference here is that you have one party responsible for the data of another. But I'm with you on not necessarily wanting the law to punish someone for this kind of negligence.
But let's go through our alternatives here for the situation at hand. This isn't a case where some criminal aims to profit from credit card fraud, or where some irreparable injury has occurred to anyone. In those cases you have an obvious need to punish the perpetrator, and there are already separate laws against such things. In this case the primary "harm" is to the reputation of a negligent party, and their costs in responding to the consequences of their own security failure. So what are our alternatives?
In the first case we can punish AT&T for allowing the vulnerability. However, there is a real problem with doing this: A small penalty will have no effect, and a penalty large enough to motivate AT&T will also be large enough to bankrupt any startup, which would increase risks and compliance costs for small businesses and quite plausibly outweigh the benefit of deterring insecurity. On top of that, if companies are punished for vulnerabilities then they may just not report them at all, even in cases of explicitly malicious attackers, which would go so far as to prevent the third parties affected from trying to mitigate the damage.
The second alternative would be to punish the party who conducts an unauthorized but mostly harmless investigation into a vulnerability without the consent of the party who negligently created it. Naturally this may deter some proportion of the people likely to engage in such behavior from doing so. However, that deterrence is not particularly productive, because it leaves the vulnerabilities in place. Someone who harvests email addresses and publishes them to prove the vulnerability shames the negligent party into fixing it before some greater harm occurs, like a more malicious party harvesting the emails to use for a phishing scheme, which achieves the converse of the original: Instead of publishing the vulnerability and causing it to be fixed with minimal harm, you have a secret but significant and continuing harm and the vulnerability may never be exposed or fixed.
A third alternative would be to do both: Punish the party that created the vulnerability and the party that demonstrates it. But that's just the worst of both worlds. You deter those who would have the vulnerability fixed and leave it open for exploitation in secret by organized crime or foreign governments, meanwhile you still impose significant legal risk and compliance costs on the economy.
Which leaves the alternative of not punishing anyone. In that case the vulnerabilities get published and the corporations are shamed into fixing them. A corporation that repeatedly suffers security vulnerabilities has its reputation destroyed and suffers in the marketplace to the degree that its customers place a value on the security of their data, providing a market-based incentive for good security. Meanwhile "attackers" who merely experiment and publish vulnerabilities are encouraged to do more of that work, but those who engage in e.g. fraud are still punished under the specific laws against that class of behavior.
Between those four, it seems to me the last is best.