As everyone has said, that was a bad idea.
You should let your members know what happened. They may have had private information stored on your site somewhere. Information that this person now has access to. Maybe they PM'd something to a friend (a bank password, credit card number, who knows) or maybe they're simply using an email address that they don't want to get out there.
A heads up that someone may have accessed that information would be expected.
|