Bug bounty programs are establishing themselves in Russia – with potentially far-reaching consequences

Bug bounty programs are establishing themselves in Russia – with potentially far-reaching consequences

A few Russian government institutions have partnered with Standoff 365 and BI.ZONE, indicating a changing perception of bug bounty programs and the Russian hacker community, which until recently was viewed as a threat to security rather than a means of improving it.

In February 2023, the Ministry of Digital Development registered 10 of its e-government systems, including Gosuslugi, the portal of state services of the Russian Federation, with both the Standoff 365 bug bounty and the Bi.ZONE bug bounty platform. The maximum payout for finding a critical vulnerability is 1 million ₽ ($11,000). According to the ministry, more than 16,000 people have signed up for the government bug bounty program, with more than 100 vulnerabilities found so far.

These federal efforts are also feeding into regional governments. In December 2023, the municipal services of Moscow Oblast (uslugi.mosreg.ru) launched their own bug bounty program on Standoff 365, the same month Rostov Oblast followed with its geographic information system (RO GIS), and the Republic of Sakha also opened its electronic services for bug hunting in May 2024. Unlike programs run by private companies, the programs associated with state institutions are open only to citizens of the Russian Federation.

Leave a Reply

Your email address will not be published. Required fields are marked *