Responsible Disclosure

The Organized Crime and Corruption Reporting Project works with dozens of investigative journalism organizations and hundreds of journalists around the globe. Security of our sources and colleagues is our top priority.

All software has bugs. We run a number of websites and services, adding up to millions of lines of code. While we strive to test and secure them as well as possible, our resources are limited. That is why we highly appreciate any responsibly disclosed information regarding potential vulnerabilities or security issues with our services.

Responsible disclosure policy

The point of contact is security@occrp.org, PGP/GPG fingerprint: 8AA2 D5B4 A0B5 B3DA E547 238C 5237 8B24 FB18 D161.

Rules

What is in scope?

Please do not report:

What to expect

Disclosure

This program allows responsible disclosure and we will work with you if you want to publish a blogpost.

Compensation

As a non-profit we are sadly unable to offer any compensation for disclosed security issues. We will however gladly give credit to anyone responsibly disclosing a security issue to us.

Hall of fame

We would like to thank all organizations and hackers who helped us, our colleagues, and our sources stay safe and secure by responsibly disclosing security issues affecting our services.

nhiephon

Found an exposed public Google Maps API link in VIS.

Aditya Soni

Reported an exposed Ruby server running in debug mode that caused an information leakage.

Kasper Karlsson

Reported a XSS vulnerability in a POST parameter on Reporting Project's People of Interest investigation.

Anon Tuttu Venus

Reported an exposed .git/config in the OCCRP website.

Shivam Pandey

Reported an problem in our external newsletter service provider.

Ratnadip Gajbhiye

Reported a misconfiguration of clickjacking protection in VIS, along with several minor issues in other OCCRP projects.

B.Dhiyaneshwaran

Reported an information disclosure issue OCCRP website.

Somil Jain

Reported, as part of the BountyFactory program for OCCRP, an e-mail related security issue with Investigative Dashboard.

Krishna Raja

Reported, as part of the BountyFactory program for OCCRP, an e-mail related security issue with Investigative Dashboard.

5P3C73R

affiliation: IT researcher from YesWeHack's BountyFactory.io

Reported, as part of the BountyFactory program for OCCRP, a security-related caching issue in VIS.

Baptiste Cauvin

Reported, as part of the BountyFactory program for OCCRP, an XSS vulnerability in VIS.

Gromak123

affiliation: IT researcher from YesWeHack's BountyFactory.io

Reported, as part of the BountyFactory program for OCCRP, an LFI vulnerability in VIS.

Thrivikram Gujarathi

Reported an SPF misconfiguration issue.

Savan

Reported a misconfiguration allowing to perform a clickjacking attack.

Milan Solanki [MasHack]

Reported, as part of the BountyFactory program for OCCRP, an authentication related security issue with Investigative Dashboard.

Sehno

Reported, as part of the BountyFactory program for OCCRP, a TLS-related issue with Investigative Dashboard.

Rahul PS

Reported, as part of the BountyFactory program for OCCRP, an authentication related security issue with Investigative Dashboard.

Rbcafe

Reported, as part of the BountyFactory program for OCCRP, a tabnapping issue with Investigative Dashboard.

Sajibe Kanti

Reported a number of misconfiguration issues in OCCRP's Secure Sign-in that could in certain very specific circumstances lead to limited unauthorized information disclosure.

SaxX

affiliation: IT researcher from YesWeHack's BountyFactory.io

Reported, as part of the BountyFactory program for OCCRP, a number of misconfiguration issues in Investigative Dashboard, including sensitive information leak.

BZHash

affiliation: IT researcher from YesWeHack's BountyFactory.io

Reported, as part of the BountyFactory program for OCCRP, a number of misconfiguration issues in Investigative Dashboard, including sensitive information leak.

joker2a

affiliation: IT researcher from YesWeHack's BountyFactory.io

Reported, as part of the BountyFactory program for OCCRP, a number of misconfiguration issues in Investigative Dashboard.

onemore

affiliation: YesWeHack

Reported, as part of the BountyFactory program for OCCRP, a number of security issues in VIS, including XSS, CSRF, and RCE vulnerabilities.

thomas__

affiliation: YesWeHack

Reported, as part of the BountyFactory program for OCCRP, a number of security issues in VIS, including an XSS vulnerability.

Special Thanks

Subscribe to our weekly newsletter!

And get our latest investigations on organized crime and corruption delivered straight to your inbox.

We need your input!👂
We’re updating our website and we would value your feedback! If you can spare 5 minutes right now to help us improve our website designs, we’d appreciate it.
👉 Leave feedback