HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification
HackerOne has ended its long-standing anonymous model for paid bug bounty programs. Researchers must now complete mandatory identity verification before submitting any reports to programs offering monetary rewards.
Compulsory Verification Becomes a Hard Requirement
Starting August 1, every hacker must finish identity verification before submitting vulnerabilities to any Bug Bounty Program. Unverified accounts cannot submit reports or receive payouts. The rule applies to all paid programs without exception. Vulnerability Disclosure Program (VDP) projects that offer no financial rewards remain open to unverified researchers.
Verification Process Handled by Veriff
Users access the ID Verification section in their profile, sign the Rules of Engagement document, and are redirected to Veriff, an Estonian identity verification provider. The process requires a live camera scan of a government-issued ID such as a passport, national ID, residence permit, or driver’s license, plus a real-time selfie for facial matching. Scanned copies and digital IDs are not accepted.
Several restrictions apply: VPNs, traffic anonymization tools, jailbroken devices, SDK emulators, and Apple Private Relay are all prohibited and trigger automatic rejection. Verification usually completes within three business days, with a maximum queue time of 48 hours. The verification must be renewed every year.
H1 Clear Adds Criminal Background Checks
H1 Clear represents a stricter tier that combines standard verification with criminal background screening. It targets a select group of elite researchers working on internal enterprise programs. Even Clear-status researchers must still complete the annual standard verification renewal.
Common Rejection Reasons and Preparation Tips
Most rejections stem from technical issues rather than identity fraud: blurry text on documents, missing machine-readable zones, cropped barcodes, expired IDs, or use of photocopies. HackerOne recommends good lighting, removal of glasses and headwear, and use of Chrome or Safari browsers.
Industry-Wide Shift Toward De-Anonymization
The change aligns with regulatory demands for anti-money laundering compliance and customer due diligence on cross-border payments. Similar verification requirements already exist on Bugcrowd and European platforms such as Intigriti. The policy affects new researchers, those in privacy-sensitive regions, and anyone hoping to participate in time-sensitive bounty competitions, as unverified accounts cannot submit reports immediately upon discovering a vulnerability.
Related articles
FAS Case Against Apple Will Not Brick iPhones for Russian Users
The Russian Federal Antimonopoly Service (FAS) has opened a case against Apple for failing to pre-install a national messenger and a Russian app store on iOS devices, yet officials have confirmed that no technical measures will disable or restrict existing iPhones. Deputy Chairman of the State Duma Committee on Information Policy Andrey Svintsov stated that the actions of FAS, Roskomnadzor and other agencies are limited to recording violations and collecting fines. Apple had already implemented the option to select a domestic search engine but did not meet the remaining pre-installation requirements. Svintsov emphasized that any court decisions will remain in force until Apple decides to return to the Russian market and settles accumulated penalties. The approach is designed to replenish the state budget through fines once the company resumes legal operations. Russian iPhone owners can continue using their devices without any risk of remote blocking or forced conversion into expensive paperweights.
Yandex Cloud Partners with Sogaz and Ingosstrakh to Automate Cyber Risk Assessment for Business Insurance
Yandex Cloud, through its Yandex B2B Tech division, has launched joint cyber insurance programs with Russian insurers Sogaz and Ingosstrakh. The initiative replaces traditional manual questionnaires with automated infrastructure scanning via the Yandex Security Deck service. The tool examines cloud resources, applications, and data to identify open internal information, excessive user privileges, leak risks, and potential compromise vectors. Detected issues are consolidated in a single prioritized interface and shared with insurers to refine policy terms. If critical gaps are found, Yandex Cloud also provides remediation recommendations. The move comes as demand for cyber insurance grows rapidly, with Sogaz reporting that requested coverage volume doubled year-over-year to exceed 12 billion rubles in the first half of 2026.
Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets
Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.
Telegram Briefly Removed from App Store After Apple Detects Child Sexual Abuse Material
Telegram was temporarily pulled from the App Store in multiple countries after Apple moderators identified content linked to child sexual abuse. The removal lasted roughly 20 minutes before the app was reinstated following Telegram's quick removal of the prohibited material and blocking of the responsible user. Apple cited strict App Store rules as the reason for the action. During the outage, already-installed copies continued to function normally while the app remained available via the Mac App Store and Google Play. Telegram responded on X with the quote “Rumors of my death have been greatly exaggerated” before Apple issued its official explanation. This marks at least the third documented instance of Telegram facing App Store removal, including a 2018 incident over unacceptable content and a 2024 removal from the Chinese store at the request of local regulators.