While I would love that for the kid I dont think these companies care about security at all.

I think that's unfair to say about a company that pays bug bounties at all.

A lot of other companies would have ignored the email for weeks or threatened legal action.

Its cheaper to pay bug bounties than to hire a security expert or legal costs