Making it a self post with the url unlinked in the description, with a warning might have been better. Suppose the site had been hacked and loaded with malware and readers assumed you were just linking a report about the hack, rather than the compromised site itself.
No harm done. This sort of thing won't be in the HN guidelines. In general, if you want to show others a compromised site, make sure the link is clearly identified as such and won't be clicked on accident. Optimally, make it so it's not really live link and the receiver will have to, say, cut and paste if they decide they want to view it. Just a bit of basic precautionary paranoia.