Earlier quoted context omitted.
From Markus' account, it sure looks like that; but note that a "chris russo" says, in the comments, that he's only given a proof of concept and that the web server logs will show that he didn't make a full dump. Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to ext…
That's a technicality in my opinion. If the website owner would ask you to fix it that would be one thing, to hack them and then to 'offer to fix it' (presumably for a fee) is across the line. It's a fine one but it's definitely there. Hacked a site? Send them a message about it, give them time to respond and time to fix. If they don't respond after a reasonable time has passed go public with it, don't try to transla…
It would be good if more companies set up bug bounties, and even better if they'd set the reward a bit closer to (reputed) black-market prices.