HackerOne

A former employee of HackerOne accessed internal data documents of the company for personal financial gain.

He obtained information from security reports submitted to the bug bounty platform and attempted to disclose the same vulnerabilities outside of the platform.

In under 24 hours, the company worked quickly to contain the incident by identifying the then-employee and cutting off his access to data after a suspicious customer received duplicated bug reports and raised complaints.

Source: https://portswigger.net/daily-swig/hackerone-employee-stole-data-from-bug-bounty-reports-for-financial-gain

"id": "HAC1486722",
"linkid": "hackerone",
"type": "Breach",
"date": "07/2022",
"severity": "80",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"