"I can't reveal the exact SQL query because that's customer private information."
That doesn't make sense.
The results of the query are probably private customer information, but the query itself has nothing to do with them (hopefully) and was simply the net the TLA was casting.
You've broken the seal by reporting that it was done at all and reporting the exact query doesn't change that.
OTOH, not reporting on what the actual query was makes me very skeptical about the whole thing.
By all means, obfuscate table names or whatever if there was a wildcard involve that matched customer defined elements (or whatever).