Anyone could steal your bus money in Seattle
evanbyrne.com
evanbyrne.com
I believe this is a generic problem with lots of organizations/companies, contacting them about possible security vulnerability is made complex or impossible while there should be a simple straightforward way.
I wouldn't be surprised if a number of vulnerabilities (besides bugs) go unreported because the user that finds them is not persistent enough in communicating abou them.