First thing is to see if the company has a bug bounty/responsible disclosure programming. If so make sure that what you have done falls under said program. Otherwise it is not worth the risk to you. If you still feel motivated to do so, let them know through anonymous channels or contact a well know security researcher who will be less of a target if said company decides to take action.