Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…
From Wes's blog post.
I don't know anything about security or about the people involved. But I read your quote, and I read the one above.
Unless Stamos explicitly disagrees with Wes's timeline of events, my interpretation of 'he has interacted with us using a synack.com email address' does not explicitly state that Wes used it in relation to the attack before the phone call to the CEO.
Happy for more evidence to be presented to show the contrary.