Skip to main content

folkfox

Skip to main content
Skip to content
BUG BOUNTY ECONOMY

LG Uplus Just Ran South Korea's First Global Vulnerability Disclosure Program

LG Uplus just paid outside hackers to hunt its own flaws before anyone else could, the first Korean telecom to run a vulnerability disclosure program at global, invite-only scale. Thirty years after Netscape's first bounty, the same instinct has reached the industry that carries everyone else's traffic.

Quick answerLG Uplus just launched a global vulnerability disclosure program with HackerOne, the first South Korean telecom to do so, paying vetted researchers to find flaws before attackers do, an idea that started with browsers three decades ago.
SECTION 01

What LG Uplus's vulnerability disclosure program actually signals#

The scale a vulnerability disclosure program now operates at

Validated vulnerabilities, all time

580000+

Reported to HackerOne's platform across its history, per its 2025 Hacker-Powered Security Report.

Estimated breach losses avoided, 2025

$3B

Roughly 15 times what programmes paid out in bounties that year, HackerOne's own estimate.

Hack the Pentagon bounties, 2016

$75000

Paid across 138 valid reports in the first bug bounty program the US federal government ever ran.

A fox does not wait for the henhouse door to fail before it starts reading the wind. On 24 August 2026, LG Uplus, one of South Korea's three major telecom carriers, launched a global vulnerability disclosure program built with HackerOne, and described itself as the first domestic telecoms company to run one at that scale, according to digitaltoday.co.kr's original report. It is a small, deliberate act of trust: paying vetted strangers to go looking for the flaw before an attacker does.

The scope covers LG Uplus's mobile, internet and enterprise services, and access is restricted to security researchers who pass identity verification and a capability assessment before they are invited in, the same report notes. The carrier already ran a domestic bug bounty program with Korea's own KISA since October 2024; what changed this week is the reach, tapping HackerOne's global community of researchers, described by the outlet as some 2.4 million strong, to cover roaming, cloud and AI services that now cross borders daily.

None of this makes a vulnerability disclosure program the same animal as a bug bounty program, though the two get used as synonyms more often than the difference deserves. It is the open door: a published channel and a promise not to prosecute the researcher who knocks on it. A bug bounty program is that same door with cash sitting on the other side of it. LG Uplus now runs both, domestically through KISA and globally through HackerOne, which is precisely why the story is worth more than a single headline.

Nor is LG Uplus the first telecom anywhere to try this. T-Mobile's own bug bounty program, run with Bugcrowd, has paid US researchers since August 2023. What is new is a Korean carrier opening its whole international footprint to a global, vetted pool of hunters at once, rather than keeping the hunt local.

A vulnerability disclosure program is the open door. A bug bounty program is cash sitting behind it.
folkfox, on why the two terms keep getting confused
SECTION 02

The three-decade trail from a browser beta to a telecom's global den#

Every trail has a first paw print, and this one belongs to Netscape. On 10 October 1995, Netscape launched what is widely recorded as the first bug bounty program, offering cash rewards to anyone who could find security bugs in the Netscape Navigator 2.0 Beta, according to Cobalt's history of bug bounty programs. Browsers were the entire internet's front door at the time, so paying outsiders to rattle the handle was a genuinely strange idea. It took the better part of two decades for anyone else to take it seriously at scale.

The next landmark belongs to the US government. HackerOne's own record of Hack the Pentagon shows the pilot ran from 18 April to 12 May 2016, with 1,410 researchers registering, roughly 250 submitting at least one report, and 138 of those reports judged legitimate, unique and eligible for a bounty. The Department of Defense paid $75,000 across those 138 reports, in amounts from $100 to $15,000 each, and called it the federal government's first bug bounty program. The fox that finds the gap in the fence does not need to be told twice where to look next time, and neither, it turned out, did Washington.

The reward has grown by orders of magnitude, but the underlying trade, cash for a found flaw, has not changed since 1995.
ProgrammeYearHeadline result
Netscape Navigator 2.01995First recorded bug bounty program, cash rewards for security bugs
Hack the Pentagon2016$75,000 paid across 138 valid reports, first US federal bug bounty program
LG Uplus with HackerOne2026First global, invite-only vulnerability disclosure program run by a Korean telecom

What sat between those two dates and this week was mostly quiet plumbing: platforms like HackerOne and Bugcrowd building the intake, triage and payment rails that let this kind of programme scale past a single company's own security team. A bug bounty platform's actual job is unglamorous. It verifies the researcher, routes the report, prices the severity and keeps both sides honest about the clock, so that the interesting work, hunting the flaw itself, is the only part anyone outside the platform ever sees.

A fox peering through a magnifying glass into shadowed undergrowth, illustrating a vulnerability disclosure program hunting for a hidden flaw
A vulnerability disclosure program works exactly like this: patient, one flaw at a time, long before an attacker starts looking.

By the time LG Uplus opened its door to HackerOne's researchers this week, the pattern was well worn: a sector under pressure, a platform built to carry the load, and a fox's patient prowl through the undergrowth swapped for a paid, structured hunt with rules both sides had agreed to in advance.

SECTION 03

What HackerOne's own numbers say about the scale of the trade#

Scepticism about whether any of this actually works is fair, so look at the platform's own disclosures rather than its marketing copy. HackerOne's 2025 Hacker-Powered Security Report puts total validated vulnerabilities at more than 580,000 across its history, drawn from roughly 1,950 enterprise programmes active in the past year, with $81 million paid out in bounties in 2025 alone. The report's own estimate of breach losses avoided across those programmes runs to $3 billion, a return the company frames as roughly 15 times what it paid out. BleepingComputer's coverage of the same $81 million figure, for the twelve months to June 2025, records a 13% year-on-year increase, with the top ten programmes alone accounting for $21.6 million of it.

Where bug bounty earnings grew fastest, one landmark year
Switzerland/Austria
+950%
APAC researchers
+250%
Federal programmes
+214%
Hacker community
+100%
Country-level researcher earnings outpaced the platform's own explosive membership growth in HackerOne's 2020 Hacker Report, with Swiss and Austrian researchers' payouts climbing nearly tenfold in a single year.

One quieter number is worth sitting with. HackerOne's own March 2021 press release put its customer count at over 2,000 programmes; its 2025 report counts roughly 1,950. The hacker community and the payouts both kept climbing, but the number of companies running a bug bounty program on the platform has been closer to flat than the growth story usually implies. A bug bounty platform's herd does not only grow, it also thins, as some organisations fold their programme into a private channel or a different vendor once the initial rush of reports settles into routine.

The researchers themselves are changing tools faster than the programme count is changing shape. The same 2025 report found 70% of surveyed researchers now use AI in their workflow, alongside a 210% jump in valid AI-related vulnerability reports and a 540% surge in prompt injection findings specifically, the fastest-growing single category HackerOne tracks. A programme built for last year's threats is already behind; the flaw worth hunting keeps changing shape faster than the fox chasing it.

SECTION 04

Why regulators keep pointing at the same policy#

Governments were slower to the den than telecoms, but they arrived with teeth. The US Cybersecurity and Infrastructure Security Agency's Binding Operational Directive 20-01, issued 2 September 2020, requires every US federal civilian agency to publish a vulnerability disclosure policy, staff a monitored contact for reports, and maintain handling procedures, with every internet-accessible system in scope by September 2022. It is a vulnerability disclosure program mandated by law rather than volunteered by a marketing team, and the compliance record is genuinely strong: FedScoop's reporting found all 101 covered agencies had published a policy, with more than 93% fully implementing the directive's requirements, and CISA crediting the resulting reports with helping to mitigate more than 3,000 vulnerabilities.

Europe is not standing still either. CERT-EU's own coordinated vulnerability disclosure policy lays out a step-by-step procedure the EU's own institutions, bodies and agencies follow whenever a flaw turns up in software they use, confirming and notifying vendors before any public word gets out. Layered on top of that, the Cyber Resilience Act's reporting deadline arrives on 11 September 2026, with full application following on 11 December 2027, and it requires manufacturers of connected products sold in the EU to run a coordinated vulnerability disclosure policy with a clear, monitored point of contact, not just a page buried three clicks from the homepage.

Put the American directive and the European regulation side by side and the message rhymes even if the wording differs: a vulnerability disclosure program is no longer a nice-to-have a security team requests once a year and rarely gets. It is fast becoming the minimum a regulator expects to find when it goes looking, on either side of the Atlantic, in a telecom's back office or a federal agency's front door alike.

SECTION 05

The trajectory a vulnerability disclosure program is riding#

Numbers scattered across three decades tell a scattered story until they sit on the same axis. HackerOne's own press releases, read one after another rather than one at a time, show hackers earning a cumulative $42 million on the platform by the end of 2018, $82 million by the end of 2019, $100 million by May 2020, and $300 million by October 2023.

Cumulative bounties paid on HackerOne
Line chart showing HackerOne's cumulative bounty payouts rising from 42 million dollars in 2018 to 300 million dollars in 2023300M200M100M0M2018201920202023Cumulative bounties paid: 42Cumulative bounties paid: 82Cumulative bounties paid: 100Cumulative bounties paid: 300
Cumulative bounties paid
Cumulative payouts climbed from $42 million in 2018 to $300 million by October 2023, a sevenfold rise as bug bounty programs spread from tech giants toward telecoms and governments alike.

That is not a smooth curve so much as a series of gates swinging open one after another: a browser vendor's beta in 1995, a government pilot in 2016, a platform quietly crossing $100 million in 2020, then trebling again by 2023, and now a telecom carrier's global infrastructure this week. Each gate widened what a vulnerability disclosure program was expected to cover, from one product to an entire agency to an entire carrier's cloud, roaming and AI estate.

What LG Uplus is really betting is that the researchers who used to hunt browsers and government portals will now hunt telecom infrastructure just as readily, for the same trade: a fair reward, a promise not to prosecute, and a scent worth following. Whether that bet pays off will show up in the same kind of number HackerOne already publishes for everyone else, valid reports, average time to fix, and money paid before a breach rather than after one.

For any regulated brand watching this trail from the outside, the marketing question is rarely whether to run a vulnerability disclosure program at all any more, it is whether the world hears about it accurately when a researcher finds something worth reporting. Vulnerability management solutions meet a 24-hour deadline covers the other half of that same clock, what happens once a flaw is confirmed and the fix has to ship before anyone can outfox the disclosure with an exploit of their own.

That is squarely where folkfox's SEO and GEO services and content marketing work sits: building the page a journalist, a regulator or a generative search summary finds first when your disclosure work does exactly what it is supposed to do. Brand strategy for security and telecom vendors increasingly means being ready to explain a disclosure calmly the same week it breaks, not three days late once the story has already been written by someone else. MDR services growing a second set of watchful eyes and AI security testing that went shopping for a weaker model are both the same instinct wearing different fur: pay someone patient to find the gap in the hedgerow before a stranger with worse intentions does.

The fox that survives the season is the one that keeps checking the same thicket even after nothing has turned up in it for months. LG Uplus just proved that instinct scales past a browser, past a government agency, all the way to the infrastructure an entire country's phones run on. The next telecom to try it will not be doing anything new. It will simply be doing the sensible thing thirty years sooner than it might otherwise have got around to.

Questions

Frequently asked questions#

What is a vulnerability disclosure program?

A vulnerability disclosure program is a published channel that invites security researchers to report flaws safely, along with a promise not to pursue legal action against a good-faith reporter. It does not always include payment. LG Uplus and CISA's federal directive both describe this exact structure.

Vulnerability disclosure program vs bug bounty: what is the difference?

A vulnerability disclosure program is the open channel and the legal safe harbour. A bug bounty program adds cash rewards on top of that same channel. LG Uplus runs both: a domestic program with KISA and a paid, invite-only global program with HackerOne.

What should a vulnerability disclosure policy template include?

A workable vulnerability disclosure policy template names the systems in scope, states what testing is and is not permitted, gives a monitored contact for reports, promises no legal action for good-faith research, and sets a rough timeline for acknowledgement and a fix.

How much do bug bounty platforms actually pay hackers?

HackerOne alone paid $81 million in bounties in 2025, part of more than $300 million paid cumulatively by October 2023. Individual payouts vary hugely, from a few hundred dollars for a minor bug to tens of thousands for a critical one.

Is LG Uplus the first telecom to run a bug bounty program?

No. T-Mobile has run a public bug bounty program with Bugcrowd since August 2023. LG Uplus is the first South Korean telecom to run one, and the first to open its whole international footprint to a global, vetted researcher pool through HackerOne.

Do governments actually require vulnerability disclosure programs?

Yes. CISA's Binding Operational Directive 20-01 has required every internet-facing US federal civilian system to sit inside a published vulnerability disclosure program since September 2022. The EU's Cyber Resilience Act adds its own mandatory reporting deadline from 11 September 2026.

Keep reading

Read more on this topic#

Ready to be heard the week your researchers find something?

The marketing and positioning layer folkfox builds is for security and telecom brands that want a disclosure story explained accurately, fast, in the same week it breaks.