The Mint.com website uses SSL encryption, and despite the latest Heartbleed security flaw, I'm sure Mint has taken steps to fix this issue and it's is safe to use.
I don't think it would be unethical. Maybe a little "ambulance chaser-esque", but it sounds like you're trying to find a solution to a problem. Sure, it may be unsolicited, but the injured person may actually need legal representation. They can always tell your firm no thanks.