Thanks a lot! It was clearly a security issue on my end,   all I can see is there was a problem uploading the blank index.html so the directory got exposed. 
But instead of alerting me, which a professional would do, you posted it publicly, not only allowing multiple people to access the data, but also run the email script over and over again, causing multiple emails per person.
Really professional thing to do. 
The whole "our emails are exposed" could be prevented if i had checked the directory integrity, or if you contacted me first instead of posting publicly right away. 
Exposure didn't "happen". You exposed it to everyone. 
Anyone who wants to contact me regarding this can send an email to 
[email protected] as i will not be participating in this discussion.