I ordered a product from a website and found that their invoice display page is completely un-protected with the order id in the query string and merely incrementing the number exposes every order. The information displayed shows email address, full billing and shipping address, and products ordered with the amount.
The site has badges on the bottom claiming "Paypal Verified", "Authorize.net Verified", "Sitelock Secure", "Google Checkout" etc., yet I cannot find out how to report such an obvious data/security breach to any of these companies. How and who should I report this to, to get the website owner to take the matter seriously?
 
     
     
    