The thing about big companies is that the person responding to the inbound communcation is usually in a totally separate department from the person who wrote the policy, and often doesn't know the policy exists. It's really hard to get a group of 50,000 people to act consistently with each other.
Of course, I hope for Starbucks' sake that it quickly backtracks and thanks this guy with at a minimum a bunch of free Starbucks and a phone call or email from the CIO or CEO. It's not in Starbucks' interest to dissuade white hat hacking, since black hat hackers don't care about Starbucks' policies.
http://www.starbucks.com/about-us/company-information/online...
That means that Homakov was likely not breaking the law, and you would expect starbacks to be more welcoming of the report.