Skip to Main Content
PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Department of Defense Forks Over $110K to Hackers Who Discovered 349 Bugs

The 'Hack U.S.' program proved very successful both for hackers' bank balances and the Defense Department's network security.

September 29, 2022
(Credit: Getty Images/Mandel Ngan)

The US Department of Defense (DoD) has paid out $110,000 in bounties and bonuses to ethical hackers who discovered 349 "actionable" vulnerabilities on its networks.

As The Record reports, the vulnerabilities were discovered at a week-long "Hack U.S." event held in July through a partnership with Hackerone. It tasked so-called white hat (ethical) hackers with finding "High" and "Critical" severity vulnerabilities on any publicly accessible information systems, including web property or data owned, operated, or controlled by the DoD.

In total, 349 actionable vulnerabilities were discovered, leading to the DoD paying out $75,000 in bounties. A further $35,000 was paid out in bonuses and awards.

Melissa Vice, the Vulnerability Disclosure Program director, said in a statement, "in just seven days, Hack U.S. ethical hackers submitted 648 reports, including numerous which would be considered critical had they not been identified and remediated during this bug bounty challenge ... This bounty challenge shows the extra value we can earn by leveraging their subject matter expertise in an incentivized manner."

Hack U.S. is just the latest successful bug bounty program run to discover vulnerabilities and make the US government's networks more secure. It all started back in 2016 with the launch of a "Hack the Pentagon" program, which discovered 138 problems.

Katie Olson Savage, deputy chief digital and artificial intelligence officer and Defense Digital Service director, said "this crowd-sourced security approach is a key step to identifying and closing potential gaps in our attack surface." We should therefore expect another DoD bug bounty to run in 2023.

Readers' Choice Awards 2021: Antivirus Software and Security Suites
PCMag Logo Readers' Choice Awards 2021: Antivirus Software and Security Suites

Like What You're Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.


Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

Sign up for other newsletters

TRENDING

About Matthew Humphries

Senior Editor

I started working at PCMag in November 2016, covering all areas of technology and video game news. Before that I spent nearly 15 years working at Geek.com as a writer and editor. I also spent the first six years after leaving university as a professional game designer working with Disney, Games Workshop, 20th Century Fox, and Vivendi.

Read Matthew's full bio

Read the latest from Matthew Humphries