Very disappointing.
Been with them for a long time and have hundreds of domains with them (none with privacy) and have had few problems - all fixed fast.
This however is major breach. It is also not like they were protecting million dollars of year of revenue from one client by throwing a $20 a year client under the bus. Even that wouldn't be right but more understandable.
I would hope this employee is fired and blacklisted from any customer service job or any job with access to private data. I know that won't happen. They should however at least get fired.
