Earlier quoted context omitted.
And getting a lesson in security for free it seems, it sucks but security is important.
Free? It would have required more effort, but they could have encrypted all the data, and then sent the key to a well-known white-hat security researcher, or someone who could be trusted to administrate important cases (they'd of course be free to ignore it). The encryption could be done on the compromised server with a forEach, so it'd be a single request. I think some people in this thread want to be a bit too "abs…
No just my Webserver/HAProxy. The difference is, don't expose services that are not meant to face the Inet directly.
Production-Type Webservers are, SSH, VPN, HAProxy etc are.
Databases, devel-webservers, NFS, Samba are not!
Sure even the best hardened Service can have vulnerabilities, but that's how life is, better have a door with a key than one without, even when someone is capable to open your door with a Lock-pick.