The definition being used here is in regards to the compromise of sensitive user data. By that definition this attack was benign since it didn't infiltrate anything, extract anything, or attempt to damage anything. It was a dry run.

The logic used to determine malicious code isn't quite the same as malicious intent. Code is quantifiable, whereas intent is intangible.

