Zomato agrees to hacker's demand — will launch bug bounty program in exchange for stolen data deletion
Context & Ripple Effects
Zomato's concession comes one day after it disclosed that 17 million email addresses and hashed passwords were stolen from its systems — a breach it is resolving not with a ransom payment but by agreeing to the hacker's demand that it formalize a vulnerability-reward program.
That puts Zomato on a path already trodden by its peers: Uber launched a bug bounty program through HackerOne in 2016, Yelp followed months later with rewards up to $15K on the same platform, and OnePlus would join in 2019. But Zomato's route — negotiating directly with an attacker who holds user data — foreshadows exactly the legal gray zone that Uber's own $100K hush-payment would expose a year later.
First-order effects
- Zomato now has to stand up a working vulnerability-disclosure program almost overnight, converting an extortion demand into standing security infrastructure while promising 17 million affected users their stolen credentials will be deleted — a promise it cannot independently verify.
Second-order effects
- Consumer platforms without a bounty program face pressure to adopt one preemptively, since Zomato's deal shows attackers increasingly expect a formal channel rather than a one-off payout — a dynamic that funnels researcher traffic toward coordination platforms like HackerOne.
Third-order effects
- Negotiated deletions-for-bounties sit uncomfortably close to the payment-for-silence territory that made Uber's disclosure legally ambiguous, pointing toward regulators eventually having to define where breach-response negotiation ends and cover-up begins.
The trend: Breach response at consumer internet companies is shifting from ad-hoc incident handling toward standing bug bounty programs, with negotiated deals like Zomato's exposing how thin the line is between reward and ransom.