/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Zomato agrees to hacker's demand — will launch bug bounty program in exchange for stolen data deletion

Paul Sawers / VentureBeat :

VentureBeat Paul Sawers

Context & Ripple Effects

Zomato's concession comes one day after it disclosed that 17 million email addresses and hashed passwords were stolen from its systems — a breach it is resolving not with a ransom payment but by agreeing to the hacker's demand that it formalize a vulnerability-reward program.

That puts Zomato on a path already trodden by its peers: Uber launched a bug bounty program through HackerOne in 2016, Yelp followed months later with rewards up to $15K on the same platform, and OnePlus would join in 2019. But Zomato's route — negotiating directly with an attacker who holds user data — foreshadows exactly the legal gray zone that Uber's own $100K hush-payment would expose a year later.

First-order effects

  • Zomato now has to stand up a working vulnerability-disclosure program almost overnight, converting an extortion demand into standing security infrastructure while promising 17 million affected users their stolen credentials will be deleted — a promise it cannot independently verify.

Second-order effects

  • Consumer platforms without a bounty program face pressure to adopt one preemptively, since Zomato's deal shows attackers increasingly expect a formal channel rather than a one-off payout — a dynamic that funnels researcher traffic toward coordination platforms like HackerOne.

Third-order effects

  • Negotiated deletions-for-bounties sit uncomfortably close to the payment-for-silence territory that made Uber's disclosure legally ambiguous, pointing toward regulators eventually having to define where breach-response negotiation ends and cover-up begins.

The trend: Breach response at consumer internet companies is shifting from ad-hoc incident handling toward standing bug bounty programs, with negotiated deals like Zomato's exposing how thin the line is between reward and ransom.