Perhaps just telling the site owner a max of 1 compromised subdomain, e.g. "We detected malware on sub.yourdomain.com" or "We detected malware on sub.yourdomain.com and potentially other subdomains." Seems like that would provide a huge benefit to people trying to be compliant without much benefit to bad guys hosting lots of malware on different subdomains.