Oh, they "just missed adding the statement with the update".
How reassuring!
I see two possible cases:
1. They have been served and are compelled to mislead their customers.
2. They are incredibly incompetent, thinking up a security mechanism that they now have mis-handled twice within a few months.
I would vastly prefer the first one. The second possibility is just too depressing.