Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

british_airways_vdp

HackerOneView on HackerOne
RawAI Enhanced
5
In Scope
3
Out of Scope
In-Scope Assets (5)
Out-of-Scope Assets (3)
AssetCategoryBounty
Testing is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by British AirwaysOTHERNo
accounts.britishairways.comURLNo
holiday.britishairways.comURLNo
Scope Changes (24)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedsecurity vulnerabilities that are identified in digital properties owned, operated, or controlled by british airways are considered in scopeOTHERIn Scope19:21
Added*.ba.comWILDCARDIn Scope19:21
Addedtesting is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by british airwaysOTHEROut of Scope19:21
Addedaccounts.britishairways.comURLOut of Scope19:21
Addedholiday.britishairways.comURLOut of Scope19:21
Added*.britishairways.comWILDCARDIn Scope19:21
Addedwww.britishairways.comURLIn Scope19:21
Addedhttp://www.britishairways.com/nxURLIn Scope19:21
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added*.ba.comWILDCARDIn Scope00:49
Added*.britishairways.comWILDCARDIn Scope00:49
Addedwww.britishairways.comURLIn Scope00:49
Addedhttp://www.britishairways.com/nxURLIn Scope00:49
Addedsecurity vulnerabilities that are identified in digital properties owned, operated, or controlled by british airways are considered in scopeOTHERIn Scope00:49
Addedtesting is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by british airwaysOTHEROut of Scope00:49
Addedaccounts.britishairways.comURLOut of Scope00:49
Addedholiday.britishairways.comURLOut of Scope00:49
Feb 21, 2026
ChangeAssetCategoryScopeTime
Added*.britishairways.comWILDCARDIn Scope19:13
Addedwww.britishairways.comURLIn Scope19:13
Addedhttp://www.britishairways.com/nxURLIn Scope19:13
Addedsecurity vulnerabilities that are identified in digital properties owned, operated, or controlled by british airways are considered in scopeOTHERIn Scope19:13
Added*.ba.comWILDCARDIn Scope19:13
Addedtesting is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by british airwaysOTHEROut of Scope19:13
Addedaccounts.britishairways.comURLOut of Scope19:13
Addedholiday.britishairways.comURLOut of Scope19:13