No, I think the opposite is true. It's a large organisation and he's not going to be able to get contact details for whoever is in a position to do anything. You send it to the staff dealing with that website, who should then forward it on to whoever is in charge of the site or reply to tell him who to contact.like to the organisation that looks after security instead of mailing HR... that would be fairly obvious no?
I think you should have a read of the blog post that Ev0 posted. It's an almost identical situation, and the chap who posted it on his blog has been widely praised for it, especially since it caused the ICO to launch an investigation into Tesco's website security, which hopefully will lead to them improving it.I think you're also missing the major point in that its not some random company we're talking about - if he actually thought that there was a serious security breach here then publicising it potentially has more serious consequences than simply shaming the organisation.
Last edited: