The notification don't need to be email. If there's no evidence of a breach, I think it would be reasonable for them to disclose into some kind of vulnerability database. Maybe someone could later determine if the vulnerability was exploited based on some data dump found on the dark web or something.