
"XXX takes security very seriously and we are vigilant about addressing security concerns."
Any time I see an official statement that tells the world a company takes security very seriously, I am sure they did not, it caused them to have some sort of exposure and they are most assuredly not going to learn from the experience. How does making your customer base and their contact info tie in to good security practice? It's not like a bad actor could harvest that information and use it for spear phishing or gain access to their accounts through already-exposed passwords from other sites because password re-use is a thing. Just a couple of issues typically explained in any corporate security orientation.