Did he cause damage or reveal it?
I dunno - I'd have to do a security review to figure that out...
If I walked into work and found in some server log signs of suspicious activity and a possible intrusion I'd report that to senior management. Then this guy would call them up and say "hey, I broke in - I just took some notes and for a fee I'll help you clean up, and don't worry - I didn't do anything other than copy data off your servers while I was in there." Then the managers would ask me "did this guy do anything besides copy data off our servers?" I would have to reply, "I dunno - we'd have to REALLY carefully check all our logs to know for sure, and we should assume that he's got the password files to every box in the server room to be safe." Then the managers would ask "can you change the passwords?" Then I'd answer, "sure, but that means changing the access credentials on all our internal applications, which means testing cycles to ensure we don't break anything else." Then the managers would say "get right on it, and keep a record of all the time anybody spends cleaning up this mess."
If a guy breaks into one of my servers, I'm not going to assume he's nice just because he claims to be. $200k isn't a lot to burn through when employees with overhead cost $90/hr.