HackerOne says an employee stole vulnerability reports submitted through its bug bounty platform and disclosed them to seven companies for financial rewards
A HackerOne employee stole vulnerability reports submitted through the bug bounty platform and disclosed them to affected customers to claim financial rewards. Source: HackerOne .
BleepingComputerIonut Ilascu
Context & Ripple Effects
HackerOne built its model around routing white-hat findings to companies for a commission, as described in its earlier marketplace for reporting security flaws. The employee incident puts the confidentiality of those submitted reports—not just the bounty payout process—at the center of the platform's value proposition.
The stakes rise as bounty work becomes a meaningful source of income for researchers, with HackerOne later reporting more than $300 million in program rewards. Customers and researchers therefore depend on the platform to handle vulnerability details before they are broadly exposed.
First-order effects
The seven companies that received reports outside HackerOne's intended workflow must assess the disclosures and their handling, while HackerOne must address a breach of trust with both customers and submitting researchers.
Researchers using HackerOne face a direct confidentiality concern: reports submitted for coordinated disclosure were accessible to an employee who used them to seek rewards.
Second-order effects
HackerOne's customers have greater reason to scrutinize who can access unpatched vulnerability reports and how the platform separates report intake from customer notification.
Later reporting that an Uber intruder reportedly downloaded all HackerOne vulnerability reports after gaining program access underscores the sensitivity of centralized report access, making access governance a competitive issue for bug-bounty platforms.
Third-order effects
Bug-bounty platforms are becoming custodians of high-value, pre-disclosure security intelligence, so their differentiation increasingly rests on provable controls over report access as well as researcher payouts.
As rewards make vulnerability research more professionalized, the industry faces a structural tension: centralized platforms improve coordinated disclosure but also concentrate a valuable archive of unpatched flaws.
The trend: Bug-bounty services are evolving from payout marketplaces into security-critical intermediaries whose handling of vulnerability data is as important as their reward programs.
HackerOne discloses security incident. The company says that a “then-employee had improperly accessed security reports for personal gain” and shared details about a vulnerability outside the platform https://hackerone.com/... https://twitter.com/...
Imagine submitting a bug report, watching it sit pending review to be closed as a dupe for someone to take your entire bug report and collect your bounty. https://twitter.com/...
If DoorDash allowed drivers to query customer details of everyone signed up, not just their active order, people would lose their minds. But bug bounty employees accessing critical vulns of customers they aren't even working on? Just a policy stopping it, no technical controls ht…
Crazy. I always made jokes about this and finally has happened. Kudos to hackerone for their work on identifying this quickly. Makes me wonder about the scenarios that don't get caught. This is for sure a type of threat that all companies with BB programs need to watch https://tw…
Kinda interesting - somebody mentioned security researchers selling their bug bounty exploits on dark web in parallel, but maybe it was this. https://hackerone.com/...
Insider threats affect every business. Transparency is praiseworthy. Yet conveniently forgetting that “policy & contractual” controls are not the same as technical access controls every time something comes up around triage access abuse is its own open bug requiring resolution. h…
Another example of the danger of insider threats. Company identified the culprit only when a customer received from the rogue employee a bug report similar to one that had been submitted through HackerOne on the same vuln. https://twitter.com/...
We've been criticized for not having a 3rd party run our bug bounty program but this is exactly why we run it ourselves. Resubmitting bugs for the bounty is the least bad thing that can happen. Worst case, the stolen bugs are sold to more serious hackers or directly exploited. ht…
This might be the first public headline of something like this that I've seen but there are many a large companies without proper authn/authz on their bug databases and not the first stolen / resold bugs. https://www.bleepingcomputer.com/ ...
Yea, we have been saying this for years. Marking a report critical then dropping it to informational, and then marking it as a duplicate and not letting you see the duplicate...I've been saying @FBI needs to investigate @Hacker0x01 for a long time. https://twitter.com/...