There's a protocol that should be followed here and disclosing information to people that aren't qualified to understand it - and certainly aren't qualified to do anything about it - typically does more harm than good. If you are not in a position to provide productive help & assistance there is simply no reason for you to know anything. You may think there is because you view yourself as some sort of victim - but you're wrong.
"AHHHH - a website is trying to steal my information BLAH BLAH BLAH" - guess what. If a nefarious group wants your credit card information and any other data ever put online about you - they already have it. You are more at risk when you think that store clerk is doing you a favor by asking to see your ID when you hand them your credit card.
And what happens if you are "hacked"? Your credit card company takes the loss (or the vendor) - I'm not interested in discussing the impacts of that at this time but bottom line is - you , the consumer, are the most protected entity in any online purchasing activity.
If the vendor's response is that they are not aware of it - it's going to take some time to track down how it got there, what it's been doing, how long, to whom, for what purpose etc etc.
None of that happens in minutes, hours or days.
Most people throwing a fit at this stage of something like this are not going to alter their perception, change their mind or act any differently to the vendor just because some information is disclosed - which makes all the negative comments and demands to know what happened essentially a waste of typing.
Now - if the vendor and their IT / Website folks are refusing to follow the protocol from their side - THAT is when all information should be made public.
Quit poking at the situation - it's been reported, the proper people know about it - now let them do what they need to do and wait patiently for information.
Does anyone really think that the vendor and R2R teams want this to stick around any longer than necessary?