• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

HackerOne Insider Defrauded Customers

You are here: Home / General Cyber Security News / HackerOne Insider Defrauded Customers
July 4, 2022

A previous worker at HackerOne applied their access to sensitive info at the bug bounty system to deliver private profits, the company has disclosed.

The unnamed individual’s process access was terminated just 24 several hours soon after a tip off from a consumer disclosed they had “improperly accessed information in very clear violation of our values, our society, our procedures, and our employment contracts.”

The business analyzed inside logs and uncovered that the then-employee, who had accessibility to HackerOne systems between April 4 and June 23 2022, contacted 7 customers in an effort to make some additional money off resubmitted vulnerability disclosures.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“The menace actor developed a HackerOne sockpuppet account and had received bounties in a handful of disclosures. Immediately after identifying these bounties as most likely poor, HackerOne achieved out to the relevant payment providers, who worked cooperatively with us to offer more details,” HackerOne spelled out.

“Following the revenue trail, we been given affirmation that the risk actor’s bounty was linked to an account that fiscally benefited a then-HackerOne staff. Investigation of the risk actor’s network targeted visitors provided supplemental evidence connecting the threat actor’s main and sockpuppet accounts.”

The firm taken off the employee’s HackerOne accounts, terminated their work and is at the moment looking at no matter whether to refer the scenario to the authorities for criminal prosecution.

The previous insider, who went by the handle “rzlr” in communications with clients, is reported to have employed “intimidating” language with them when anonymously disclosing vulnerabilities that experienced presently been observed and disclosed.

A analyze very last year found that a 3rd (33%) of claimed information breaches associated somebody with authorized access to the impacted details, although in most scenarios, this led to unintended knowledge loss instead than intentionally destructive action.


Some sections of this short article are sourced from:
www.infosecurity-journal.com

Previous Post: «universities are fighting a cyber security war on multiple fronts Universities are fighting a cyber security war on multiple fronts
Next Post: Security experts ‘concerned’ over compromise of British Army’s social media accounts security experts 'concerned' over compromise of british army's social media»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.