How old are you? are you working in the IT security field? have any certificates that prove you know what you are doing? these things influence the outcome of the reply mail (from thanks and plz come consult for us to get lost and you will hear from our lawyers).
another possibility: if you are not in it for the credits report it anonymously. just send an email and let them decide what to do with it...
good luck and let us know what you decide (if possible).
Update::
Had decided to do an anonymous email, but didn't need to...
Guess this person had discovered the problem, or someone else was nice enough to fill them in. To answer the questions above
I am 25
I am working as a SysEng (& IRT Member of the org)
Added certs to my signature.
I was hoping for the former. Don't really care about the cred, but I did want them to ask for some help so that I could get some real world experience. The only experience I am getting now is from the IRT. Want to do as much as I can in the security spectrum so that I can decide where I would like to specialize.
Thanks for all of the responses!