Earlier quoted context omitted.
Who cares if it has your data in it or not. Just report it to authorities and the guy who runs haveibeenpwned. Plus what are you going to do with credit card applications anyway? Sell them to a marketing company with some phony story? Or the 'sell them on the darknet to fraudsters in Russia' angle? Unless you're already involved in some dirty business already this isn't very valuable.
I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.
Reading the mistakes made in the hack itself makes me wonder if black markets and money laundering are a skill they posses.