It is not that simple if you want to stay compatible with clients that are not updated yet and are not capable of receiving unencrypted messages. You also have a risk of breaking something, so you need to test compatibility of all versions etc. The company promised security for all other users, so it probably wants to remove security only for one specific user, otherwise it faces popularity loss. The cost of properly removing encryption from an established network protocol used almost constantly over time is really high.