This is dangerous and if the fastest way to fix it puts him out of business, so be it. I would absolutely put the financial safety of thousands of customers over the financial safety of one business owner.
If the company in question is storing personal financial details on users? Sure. But credit card numbers? Please. Home Depot lost 56 million CC numbers, and the world did not come to a screeching halt.
It's exceedingly hard to clear up identity theft. It takes years, and an enormous amount of time that's taken out of your personal and work time.
It's a sad world when you can't send someone who (as far as I can see so far) may just have made an honest mistake or hired the wrong "expert" help a friendly mail, to warn them of something you have (apparently legitimately) discovered that could get them and/or their customers in trouble, all because CYA and Fear The Lawyers.
So I vote for sending the quiet e-mail first, for the same reasons as I'd privately disclose any security vulnerability before making a public song and dance about it. The goal here apparently isn't to screw the other guy, it's to fix the problem. If you can do that by raising awareness courteously with the people who are best placed to apply that fix, isn't that a better strategy than shooting first and dealing with an industry that starts systematically concealing bad practice later?