The problem I have with this scenario is that the info this person is intending on releasing... How do they even know it's actually the hacker's? A decent hacker would have the skill and thought that covering their tracks is a good idea.
I mean hacking is not exactly legal (nor is releasing another person's private info). But in this case if the person doesn't know that it's actually the hacker's then all this person might do is make some poor innocent person the victim of some very vicious attacks, hatemail, threats, etc... For what? Because the hacker covered their tracks and left this person as the fall-guy/girl.
Instead I think a proper route to take would be to forward the information onto the local cyber crimes division (and possibly the cyber crimes division nearest to the suspected hacker's location and let them sort through the issue.) In the mean time, it'd be a good idea to focus on fortifying the defenses to make it harder for the hacker to get in and mess with the server.