Cyber Security News

HackerOne Requires ID Verification for Bug Bounty Program Submissions

HackerOne has introduced identity verification as a requirement for researchers submitting vulnerability reports to bug bounty programs on its platform.

The company clarified that the new development concerns eligibility to submit reports—not identity checks connected with receiving bounty payments. Verification for reward payments is an established requirement driven by applicable financial and regulatory obligations.

Under the updated policy, researchers must complete HackerOne’s identity-verification process before submitting to a bug bounty program. Public vulnerability disclosure programs are not affected and remain accessible without identity verification.

HackerOne said the change is intended to reduce low-quality submissions, help valid vulnerability reports reach programs and move through validation more quickly, and ensure that the professional reputations researchers build remain associated with their verified identities.

Bug Bounty Programs and VDPs Remain Distinct

The updated requirement applies to bug bounty programs, which offer financial or other rewards for eligible vulnerability reports.

Vulnerability disclosure programs operate differently. They provide a formal channel for reporting security flaws but do not necessarily offer monetary rewards. According to HackerOne’s updated identity-verification documentation, VDPs will remain open to the public and will not require identity verification.

Researchers seeking reward payments must also be verified to satisfy regulatory requirements. However, that payment-related requirement is not new and should be distinguished from the newly expanded verification requirement for bug bounty submissions.

The change means researchers can continue reporting vulnerabilities through public VDPs without completing the process, but participation in bug bounty programs now requires a verified identity.

How HackerOne’s Verification Process Works

Researchers can begin verification from the ID Verification section of their HackerOne user profile.

Before starting, they must accept HackerOne’s Rules of Engagement and consent to the processing of their information by Veriff, HackerOne’s identity-verification provider. The researcher is then redirected to Veriff to complete the identity check.

Applicants generally need a valid physical identity document, such as a passport, national identity card, residence permit, or driver’s license. Supported document types can vary by country, and photocopies or digital copies are not accepted.

Researchers may also be asked to complete a live selfie or present their identity document using a device camera. The process must be completed by the person named on the relevant tax documentation; a third party cannot complete verification on someone else’s behalf.

HackerOne advises applicants not to use:

  • A VPN
  • A traffic anonymizer
  • An SDK emulator
  • A jailbroken device
  • The private reply function on an iOS device

Using any of these during verification may result in rejection.

Veriff confirms whether the information-collection session was completed successfully, but that confirmation does not mean the identity has been approved. HackerOne sends the final verification status separately, usually within three business days.

The company advises researchers with a pending status to wait up to 48 hours before contacting support.

Verification Must Be Renewed Annually

Identity verification remains valid for 12 months. HackerOne asks researchers to renew approximately one month before their verification status expires.

Researchers may also need to renew before the identity document used during the original process expires.

If verification lapses, the researcher can lose access to programs that require it, and the green verification badge will be removed from the researcher’s HackerOne profile.

Researchers participating in H1 Clear must also maintain their annual identity verification. H1 Clear is a separate, more extensive screening program involving a criminal background check, while standard identity verification is available to all eligible researchers.

Common Reasons for Verification Failure

HackerOne’s documentation identifies several issues that can prevent successful verification, including:

  • Expired or damaged identity documents
  • Blurry or poorly illuminated photographs
  • Cropped or unreadable barcodes
  • An incomplete machine-readable zone
  • Photocopies or scanned documents
  • Unsupported document types
  • Problems completing the requested selfie
  • Use of a VPN, anonymizer, emulator, or unsupported device configuration

Applicants must currently be at least 18 years old to use the identity-verification service.

Researchers whose verification fails can generally try again. After two unsuccessful attempts, HackerOne advises contacting its support team to request another verification link.

Reducing Noise While Preserving Public Disclosure

The policy introduces a verified-identity requirement within HackerOne’s reward-based bug bounty ecosystem while keeping public vulnerability disclosure channels open.

For security teams, the change is intended to improve the quality and traceability of submissions reaching bug bounty programs. For researchers, verification helps preserve the connection between their work, reputation, and platform identity.

The key distinction is that regulatory identity checks for bounty payments already existed. The new policy extends identity verification to the act of submitting reports to bug bounty programs, while public VDP submissions remain available without it.

Correction: An earlier version of this article incorrectly characterized the expanded submission requirement as being driven by regulations governing reward payments. HackerOne clarified that payment verification is not new. The new policy requires identity verification to submit reports to bug bounty programs.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago