pull down to refresh

Yeah - saw that.

It's likely that they don't know because according to the screenshot it is IDOR - i.e. unsecured, publicly accessible, file URLs. So it's not like someone hacked something, it was just sitting out there for anyone to download.