Absolutely, but mostly for their protocols, statements, people and infrastructure.

A file exfiltration vulnerability is still noteworthy.