I think the problem here is that the hacker's "responsible disclosure practice" never filtered down to a part of the organization that was in a position to care, understand and respond.
Merely sending a emails and awaiting a response (if that's what happened) is an ineffectual tactic as it depends on a chain of unaccountable people within the org making the right decision about who to forward the email to.
Merely sending a emails and awaiting a response (if that's what happened) is an ineffectual tactic as it depends on a chain of unaccountable people within the org making the right decision about who to forward the email to.