Microsoft expands its Bug Bounty schemes with higher rewards, bonuses, and new eligible software
Jason Shirk / Microsoft Security Response Center :
Context & Ripple Effects
This 2015 announcement is the opening move of what has become a decade-long escalation in how Microsoft buys vulnerability research. The expansion — higher top rewards, bonuses, and newly eligible software — set the template that later steps kept raising: a HackerOne partnership with faster payouts and a $50K max in 2019, an Xbox-specific program in 2020, and up to $26K more for high-impact Office 365 bugs by 2022.
Why it matters now: the program's scale and scope have grown to match Microsoft's attack surface — $17M paid to 344 researchers across 59 countries in a single year — and the latest round extends eligibility to critical flaws in third-party code affecting its online services, pulling the supply chain into bounty scope. The 2015 decision to broaden both pay and product coverage is where that trajectory started.
First-order effects
- Security researchers immediately face richer payouts across more Microsoft software, shifting their effort allocation toward Microsoft's expanded eligible surface.
- Microsoft's internal teams receive more external reports on the newly covered products, moving vulnerability discovery for those products from internal-only to crowdsourced.
Second-order effects
- Rival platform vendors face competitive pressure to match reward levels or lose researcher attention to Microsoft's surface, turning bounty tables into a recruiting tool for security talent.
- Brokerage platforms like HackerOne gain a validated commercial channel, which Microsoft's later partnership confirmed — intermediaries capture part of the growing payout pool.
Third-order effects
- If the pattern holds, bounty programs stop being PR gestures and become core security infrastructure whose scope tracks the vendor's full stack — Microsoft's extension to third-party code in online services points toward vendors underwriting security for their entire ecosystem, suppliers included.
- A professionalized global researcher market emerges around these programs, with payouts large and frequent enough ($200K top awards per the recent figures) to sustain independent security careers and reshape where defensive talent works.
The trend: Vulnerability disclosure is shifting from ad-hoc goodwill payments to a scaled, professionally intermediated market where vendors like Microsoft compete on reward size and scope to secure ever-larger attack surfaces.