How to respond
Don’t pay unverified submissions
We recommend against paying unverified beg bounty submissions. Documented cases show that initial payments may be followed by escalating demands. In one reported case, the demand increased from $500 to $5,000 with increasingly aggressive language. Paying once may also mark your business as receptive to further approaches.
Don’t engage if there is no verifiable detail
If a submission provides no verifiable technical detail and demands payment upfront, do not respond.
Publish a vulnerability disclosure policy
A clear vulnerability disclosure policy on your website can help reduce uncertainty and unwanted submissions. The policy should explain how security issues can be reported, what information is required, and whether your business pays bounties. If your business does not pay bounties, say so clearly.
Educate non-technical employees
Legal, finance, executive support, and other non-technical employees are often the first point of contact. They should know not to make any payment or commitment without review by the appropriate technical or security contact.
Verify independently
If a submission references a specific issue, have technical employees assess whether it exists before the conversation continues. Do not rely only on the sender’s severity rating or description.
Remediate verified findings
If a submission is technically verified, focus on fixing the issue. There is no legal obligation to pay an unsolicited researcher. There is also no obligation to tell them once the issue has been remediated.
Get a second opinion
If your business has limited internal capability to assess a submission, or the finding is unclear, seek advice from a trusted external security provider before responding.
Reduce your exposure
Most beg bounty campaigns rely on automated scans finding low-hanging fruit. Keeping systems patched, hardening internet-facing services, and reviewing your external attack surface can reduce what these tools find and make your business less attractive to beg bounty operators.