That's pretty bad, but frankly he could have communicated better to Emirates. If I was working as first line support and received that message with "omg do you know you are sharing fields a, b and c to partners. And maybe you are sharing with x, y and z also?" , without any technical details at all, I would also give a canned response, tag it as tinfoil hat and throw it into the junk.
"In the wake of responsible behaviour, on discovering these serious security flaws that violate user-data privacy, I decided to flag them to Emirates through Twitter DM in October 2017. Please note that I could not find a dedicated channel for reporting security bugs on Emirates website.
I also wrote an email to the Product Manager highlighting the security flaws. I was met with a deafening silence."