If the company is in the US it may be illegal for them to not send out security breach notices.

http://www.csoonline.com/article/221...State_By_State