So get this: the CEO of a Certificate Authority, which control the lock icon of your browser, sent >20k private keys via email, unencrypted. How hard can you show your incompetence and make clear that you had no place running that business in the first place?!?
https://www.digicert.com/blog/digicert-statement-trustico-certificate-revocation/