Uber's security team paid $100,000 to the attackers who stole 57 million user records by routing the payment through their HackerOne bug bounty programme, falsely classified as a legitimate vulnerability report. The payment was intended to conceal the breach. The CSO who authorized this was convicted of obstruction of justice and sentenced to three years of probation. Bug bounty payments to attackers who have already stolen data constitute obstruction of a federal investigation. If you receive an extortion demand, contact your legal team and law enforcement immediately. Never use a bug bounty platform to pay a criminal — it does not legitimise the payment.
Tags