Vulnerability coordination and bug bounty platform HackerOne disclosed that the firm’s former employee had stolen vulnerability reports submitted through the bug bounty platform for personal gain.
The person anonymously disclosed this vulnerability information outside the HackerOne platform with the aim of claiming additional bounties.
The firm however, has worked quickly to contain the incident by identifying the then-employee and cutting off access to data within 24 hours.
The employee, who had access to HackerOne systems between April 4 and June 23, 2022, for triaging vulnerability disclosures associated with different customer programs, has since been terminated by the San Francisco-headquartered company as of June 30.
On June 22, HackerOne responded to a customer request to investigate a suspicious vulnerability disclosure through an off-platform communication channel from someone using the handle “rzlr.” The customer had noticed that the same security issue was previously submitted through HackerOne.
Subsequently, analysis of internal log data used to monitor employee access to customer disclosures traced the exposure to a rogue insider, whose goal was to re-submit duplicate vulnerability reports to the same customers using the platform to receive monetary gains.
The rogue employee had contacted about half a dozen HackerOne customers and collected bounties for some of the reports they submitted.
Following the money trail, the firm received confirmation that the threat actor’s bounty was linked to an account that financially benefited a then-HackerOne employee. Analysis of the threat actor’s network traffic provided supplemental evidence connecting the threat actor’s primary and sockpuppet accounts.
HackerOne noted that its former employee had used “threatening” and “intimidating” language in their interaction with customers and urged customers to contact the company if they received disclosures made in an aggressive tone.
HackerOne had individually notified customers about the exact bug reports that were accessed by the malicious party along with the time of access, while emphasizing it found no evidence of vulnerability data having been misused or other customer information accessed.
Image Credit : Hackerone/Twitter















Comments