Just to be clear, I wouldn't recommend buying a Ledger device to anyone, especially after the major data leak from their ecommerce database last year and this latest fiasco with the Ledger recover service. However, if he's comfortable with his current hardware device and doesn't plan on getting a new one, there doesn't seem to be any immediate danger (at least as far as we know) that would require him to stop from continuing to use it.
I completely agree, the leaking of all that data along with what they have done now is more than enough warning that this company should not be trusted. Accordingly, I don't think anyone should feel comfortable (safe) using this HW to store large values, because when it comes to Ledger, the only question is what will be the next big scandal. Of course, I don't think that anyone should be in a panic and make hasty decisions, but everyone should start looking for other solutions, whether it's a new HW or using an old PC/laptop as an airgapped device.