Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

british_airways_vdp

HackerOneView on HackerOne
RawAI Enhanced
5
In Scope
3
Out of Scope
In-Scope Assets (5)
Out-of-Scope Assets (3)
AssetCategoryBounty
Testing is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by British AirwaysOTHERNo
accounts.britishairways.comURLNo
holiday.britishairways.comURLNo
Scope Changes (24)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.ba.comWILDCARDIn Scope19:21
Addedtesting is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by british airwaysOTHEROut of Scope19:21
Addedaccounts.britishairways.comURLOut of Scope19:21
Addedholiday.britishairways.comURLOut of Scope19:21
Added*.britishairways.comWILDCARDIn Scope19:21
Addedwww.britishairways.comURLIn Scope19:21
Addedhttp://www.britishairways.com/nxURLIn Scope19:21
Addedsecurity vulnerabilities that are identified in digital properties owned, operated, or controlled by british airways are considered in scopeOTHERIn Scope19:21
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added*.ba.comWILDCARDIn Scope00:49
Added*.britishairways.comWILDCARDIn Scope00:49
Addedwww.britishairways.comURLIn Scope00:49
Addedhttp://www.britishairways.com/nxURLIn Scope00:49
Addedsecurity vulnerabilities that are identified in digital properties owned, operated, or controlled by british airways are considered in scopeOTHERIn Scope00:49
Addedtesting is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by british airwaysOTHEROut of Scope00:49
Addedaccounts.britishairways.comURLOut of Scope00:49
Addedholiday.britishairways.comURLOut of Scope00:49
Feb 21, 2026
ChangeAssetCategoryScopeTime
Added*.britishairways.comWILDCARDIn Scope19:13
Addedwww.britishairways.comURLIn Scope19:13
Addedhttp://www.britishairways.com/nxURLIn Scope19:13
Addedsecurity vulnerabilities that are identified in digital properties owned, operated, or controlled by british airways are considered in scopeOTHERIn Scope19:13
Added*.ba.comWILDCARDIn Scope19:13
Addedtesting is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by british airwaysOTHEROut of Scope19:13
Addedaccounts.britishairways.comURLOut of Scope19:13
Addedholiday.britishairways.comURLOut of Scope19:13