If they have not shared the entire list of emails with any one third party vendor, they can reasonably rule out the data coming from any vendor.
So come out and say that, instead of this deliberately vague "no leak from
our own servers" nonsense. This is the same kind of nonsense they pulled during the KYC leak Binance experienced back in 2019. They called it a "false leak", and their statement said "At the present time, no evidence has been supplied that indicates any KYC images have been
obtained from Binance". (Emphasis mine). Just as with this hack, that statement is true but deliberately worded to obfuscate things - data was not obtained from Binance, just has it has not been obtained from CMC. And as we all know with the Binance leak, it was some sketchy third party that they sent the data to who ended up being the culprit. And just as they were responsible for that KYC leak from a third party, they are responsible for this email leak from a third party.
I also don’t know that CMC would have the ability to force their vendors to be subject to intrusive audits by another third party, when they never even had access to the data that was leaked.
Binance have a responsibility to protect your data, and that includes checking the security practices of the third parties they share your data with. If a third party is unwilling to demonstrate their security is up to scratch, then why the hell are Binance sending your data to them? This is just negligent.