Microsoft says it will pay up to $26K more, an increase of 30% in some cases, in bug bounties for “high-impact” bugs in its Office 365 products
Jessica Lyons Hardcastle / The Register :
Context & Ripple Effects
This raise extends a decade-long ratchet in how Microsoft prices vulnerability discovery. The company has repeatedly widened the program since its 2015 bounty expansion with higher rewards and new eligible software, then partnered with HackerOne in 2019 while lifting max rewards from $15K to $50K (the HackerOne partnership).
The money involved has grown with it: $13.6M paid to 341 researchers in mid-2021, rising to $17M across 344 researchers by mid-2025. The new Office 365 premium targets the product line where Microsoft's commercial exposure is densest, and it lands alongside December's move to make critical bugs in third-party code affecting its online services eligible too.
First-order effects
- Security researchers weighing where to spend their time now see a materially higher per-bug payoff on Office 365 specifically, tilting researcher effort toward Microsoft's cloud productivity stack.
- Microsoft's own cost of acquiring high-impact vulnerability reports rises immediately, an explicit trade of cash for faster disclosure on products serving its enterprise base.
Second-order effects
- Rival platform vendors running their own bounty programs face pressure to reprice high-severity cloud and productivity bugs or watch top researchers concentrate on Microsoft's higher-paying surface.
- Brokers and gray-market buyers of Office 365 exploits lose some marginal supply to the legal channel as the legitimate price floor climbs.
Third-order effects
- If the pattern holds — repeated raises, a broker partnership, and eligibility stretching into third-party code — bug bounties harden from PR gesture into a standing procurement channel where Microsoft effectively sets market rates for vulnerability discovery on its platforms.
- That pricing power concentrates with whoever owns the affected product: as more critical code paths run inside hyperscaler clouds, independent researchers' economics increasingly follow each vendor's bounty schedule rather than a market-wide rate.
The trend: Microsoft is converting its bug bounty program into a primary, repriced sourcing channel for cloud-product vulnerabilities, with payouts and eligible scope expanding nearly every year.