HackerOne has introduced identity verification as a requirement for researchers submitting vulnerability reports to bug bounty programs on its platform.
The company clarified that the new development concerns eligibility to submit reports—not identity checks connected with receiving bounty payments. Verification for reward payments is an established requirement driven by applicable financial and regulatory obligations.
Under the updated policy, researchers must complete HackerOne’s identity-verification process before submitting to a bug bounty program. Public vulnerability disclosure programs are not affected and remain accessible without identity verification.
HackerOne said the change is intended to reduce low-quality submissions, help valid vulnerability reports reach programs and move through validation more quickly, and ensure that the professional reputations researchers build remain associated with their verified identities.
The updated requirement applies to bug bounty programs, which offer financial or other rewards for eligible vulnerability reports.
Vulnerability disclosure programs operate differently. They provide a formal channel for reporting security flaws but do not necessarily offer monetary rewards. According to HackerOne’s updated identity-verification documentation, VDPs will remain open to the public and will not require identity verification.
Researchers seeking reward payments must also be verified to satisfy regulatory requirements. However, that payment-related requirement is not new and should be distinguished from the newly expanded verification requirement for bug bounty submissions.
The change means researchers can continue reporting vulnerabilities through public VDPs without completing the process, but participation in bug bounty programs now requires a verified identity.
Researchers can begin verification from the ID Verification section of their HackerOne user profile.
Before starting, they must accept HackerOne’s Rules of Engagement and consent to the processing of their information by Veriff, HackerOne’s identity-verification provider. The researcher is then redirected to Veriff to complete the identity check.
Applicants generally need a valid physical identity document, such as a passport, national identity card, residence permit, or driver’s license. Supported document types can vary by country, and photocopies or digital copies are not accepted.
Researchers may also be asked to complete a live selfie or present their identity document using a device camera. The process must be completed by the person named on the relevant tax documentation; a third party cannot complete verification on someone else’s behalf.
HackerOne advises applicants not to use:
Using any of these during verification may result in rejection.
Veriff confirms whether the information-collection session was completed successfully, but that confirmation does not mean the identity has been approved. HackerOne sends the final verification status separately, usually within three business days.
The company advises researchers with a pending status to wait up to 48 hours before contacting support.
Identity verification remains valid for 12 months. HackerOne asks researchers to renew approximately one month before their verification status expires.
Researchers may also need to renew before the identity document used during the original process expires.
If verification lapses, the researcher can lose access to programs that require it, and the green verification badge will be removed from the researcher’s HackerOne profile.
Researchers participating in H1 Clear must also maintain their annual identity verification. H1 Clear is a separate, more extensive screening program involving a criminal background check, while standard identity verification is available to all eligible researchers.
HackerOne’s documentation identifies several issues that can prevent successful verification, including:
Applicants must currently be at least 18 years old to use the identity-verification service.
Researchers whose verification fails can generally try again. After two unsuccessful attempts, HackerOne advises contacting its support team to request another verification link.
The policy introduces a verified-identity requirement within HackerOne’s reward-based bug bounty ecosystem while keeping public vulnerability disclosure channels open.
For security teams, the change is intended to improve the quality and traceability of submissions reaching bug bounty programs. For researchers, verification helps preserve the connection between their work, reputation, and platform identity.
The key distinction is that regulatory identity checks for bounty payments already existed. The new policy extends identity verification to the act of submitting reports to bug bounty programs, while public VDP submissions remain available without it.
Correction: An earlier version of this article incorrectly characterized the expanded submission requirement as being driven by regulations governing reward payments. HackerOne clarified that payment verification is not new. The new policy requires identity verification to submit reports to bug bounty programs.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…