{"id":"dc9a1241-7cf9-4b0a-adf8-4887db6bc632","engagementId":"10c8f90b-6add-4571-b54b-e515c951d4e3","data":{"brief":{"id":"20957386-8222-4320-930b-468aaf14ed00","name":"HSBC Vulnerability Disclosure Program","tagline":"HSBC Bank plc is one of the largest banking and financial services organisations in the world.  HSBC welcomes the identification of vulnerabilities that can assist us in creating a safer internet for our customers.","description":"\u003cp\u003eHSBC is one of the largest banking and financial services organisations in the world, with operations in 64 countries and territories. HSBC welcomes the identification of vulnerabilities that can assist us in creating a safer internet for our customers.\u003c/p\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"b3d6ff0b-119e-4f5b-9c38-ee13f125fc52","targetsOverview":"\u003cp\u003eThis programme can be used to report any vulnerability you reasonably believe belongs to HSBC Bank plc. Please take care when following links on HSBC websites, as these may lead you to other partner organisations.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eCurrently this program is running as non-authenticated. If you were to utilize credentials that you own it could result in your bank account being locked out as fraud. \u003cstrong\u003eIt is highly  recommended that you should not use your HSBC account if you have one.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eAdditional Rules:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReport any findings as soon as possible, please include a detailed report with Proof of Concept (PoC)\u003c/li\u003e\n\u003cli\u003eThe use of automated scanners and tools to find vulnerabilities is strictly not allowed. HSBC requests that researchers do not perform automated/scripted testing against our customer forms (Contact Us) which is used by our customers to contact our support teams.\n\n\u003cul\u003e\n\u003cli\u003ePlease do not port scan any of the HSBC assets. \u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eDo not use automated tools and scripts that could cause a service impact to any of our systems. \u003c/li\u003e\n\u003cli\u003eIf the identification of a vulnerability provides access to sensitive data, such as Personal Identifiable Information (PII) or proprietary information, please limit the amount of data you access to the minimum required to provide proof of vulnerability and cease testing. Please submit a report immediately.\u003c/li\u003e\n\u003cli\u003eHSBC VDP (Vulnerability Disclosure Program) has a strict non-disclosure policy. No vulnerability is to be displayed in any public domain.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication Issues\u003c/li\u003e\n\u003cli\u003eSQL Injection\u003c/li\u003e\n\u003cli\u003eBroken Authentication\u003c/li\u003e\n\u003cli\u003eBroken Access Control\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery\u003c/li\u003e\n\u003cli\u003eInjection vulnerabilities\u003c/li\u003e\n\u003cli\u003eIdentification of private keys and sensitive data on Github repositories\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eMarks and Spencers (M\u0026amp;S) operations other M\u0026amp;S Bank (e.g., M\u0026amp;S Retail)\u003c/li\u003e\n\u003cli\u003eDMARC/SPF Issues\u003c/li\u003e\n\u003cli\u003eThird party integrations\u003c/li\u003e\n\u003cli\u003eDenial of Service / Spamming\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues\u003c/li\u003e\n\u003cli\u003eDo not attack our end users, or engage in the trade of stolen/breached user credentials.\u003c/li\u003e\n\u003cli\u003eVulnerabilities caused by the use of of outdated browsers.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories.\u003c/li\u003e\n\u003cli\u003eEmail Spoofing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please reach out to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e7fefe7a-0913-4a38-9c7a-36f3b32e8fc0","name":"In scope targets","targets":[{"id":"5a25fd18-d2cb-471e-bc0f-72715a9fc556","uri":"","name":"HSBC Bank plc, and all its brands and subsidiaries","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"405b8449-1661-457d-a7b9-acdee1938ab5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eHSBC Bank plc, and all its brands and subsidiaries including (but not limited to):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFirst Direct\u003c/li\u003e\n\u003cli\u003eHang Seng (including Hang Seng Bank and the Hang Seng Index)\u003c/li\u003e\n\u003cli\u003eINKA KAG\u003c/li\u003e\n\u003cli\u003eM\u0026amp;S Bank only (Marks and Spencers (M\u0026amp;S) operations other M\u0026amp;S Bank (e.g., M\u0026amp;S Retail) are \u003cstrong\u003eNOT IN SCOPE\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003ePayMe \u003c/li\u003e\n\u003cli\u003eSaudi Awwal Bank (formerly Saudi Arab British Bank and Alawwal Bank)\u003c/li\u003e\n\u003cli\u003eTrinkaus \u0026amp; Burkhardt AG\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eScope Examples:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eNote: This is not a comprehensive list, just some examples\u003c/strong\u003e\u003cbr\u003e\n\u003ccode\u003e*.hsbc.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.hsbc.co.*\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.firstdirect.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.hangseng.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.hsi.com.hk\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.inka-kag.de\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.bank.marksandspencer.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.payme.hsbc.com.hk\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.sab.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.hsbctrinkhaus.de\u003c/code\u003e\u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003eYou may also report vulnerabilities in technical domains operated by HSBC, including \u003ccode\u003enic.hsbc\u003c/code\u003e, the \u003ccode\u003e.hsbc\u003c/code\u003eTop Level Domain, all subdomains of \u003ccode\u003e.hsbc\u003c/code\u003e, and:\u003cbr\u003e\n\u003ccode\u003e*.byodmobile1865.{com,net}\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.dpwaf.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.maplequad.com\u003c/code\u003e\u003cbr\u003e\n\u003ccode\u003e*.vv1865.com\u003c/code\u003e\u003c/p\u003e\n\u003c/blockquote\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"f8c5b790-65ae-4c65-a2e5-c28cddec91f8","name":"Out Of Scope","targets":[{"id":"32580fd1-2e6b-46b5-8739-46e456a36517","uri":"","name":"Marks and Spencers (M\u0026S) operations other M\u0026S Bank","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"089874d5-2356-47f4-bafd-10ea80fc7ca1","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAll Marks and Spencers (M\u0026amp;S) \u003cstrong\u003eoperations\u003c/strong\u003e are out of scope.\u003cbr\u003e\nOnly the Marks and Spencers (M\u0026amp;S) BANK is in scope, strictly adhere to this.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"10c8f90b-6add-4571-b54b-e515c951d4e3","code":"hsbc-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"23ddc9f3-d358-455f-ada0-cfdbeda179e5","startsAt":"2024-09-27T09:17:15Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Banking","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/321e/8aea/d8913dce/50d989972aa7a6b869dd16b5cfc81a56_image003.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-09-27T09:17:15.061Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/hsbc-vdp-pro","changelogs":"/engagements/hsbc-vdp-pro/changelog","submissions":null,"announcements":"/engagements/hsbc-vdp-pro/announcements","hallOfFame":"/engagements/hsbc-vdp-pro/hall_of_fames","crowdstream":"/engagements/hsbc-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/hsbc-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=hsbc-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/hsbc-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/hsbc-vdp-pro/changelog","publishedAt":"2025-10-15T15:10:51.467Z","engagementChangelogUrl":"/engagements/hsbc-vdp-pro/changelog/dc9a1241-7cf9-4b0a-adf8-4887db6bc632","createUserFeedbacksUrl":"/engagements/hsbc-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/hsbc-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}