swiss-post

YesWeHackView on YesWeHack
RawAI Enhanced
11
In Scope
5
Out of Scope
In-Scope Assets (11)
Out-of-Scope Assets (5)
AssetCategoryBounty
Any services related to Incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHERYes
Anything that has not been described as in scope in the previous section is automatically out of scope.OTHERYes
Attacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes DNS, NTP, routers, systems of the ISP, etc.).OTHERYes
Please note that some of the applications may contain links or redirect you away from the URIs described in the scope section. This means you are leaving the scope if you follow these links / redirects.OTHERYes
The alternative login (https://login.swissid.ch) is out of scope. It also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scope.OTHERYes
Scope Changes (55)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://shop.post.ch/shopURLIn Scope19:08
Addedhttps://billingonline.post.ch/OnlinePayment/Web/v1/BOIURLIn Scope19:08
Addedhttps://service.post.ch/zopa/appURLIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=ch.post.it.pcc&hl=enANDROIDIn Scope19:08
Addedanything that has not been described as in scope in the previous section is automatically out of scopeOTHEROut of Scope19:08
Addedthe alternative login (https://login.swissid.ch) is out of scope. it also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scopeOTHEROut of Scope19:08
Addedhttps://service.post.ch/ele-klp/eleURLIn Scope19:08
Addedany services related to incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHEROut of Scope19:08
Added(*.post.ch:80|*.post.ch:443) and 194.41.128.0/17WILDCARDIn Scope19:08
Added(*.post.ch:80|*.post.ch:443) and 194.41.128.0/17WILDCARDIn Scope19:08
Addedhttps://apps.apple.com/ch/app/die-post/id378676700IOSIn Scope19:08
Addedattacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes dns, ntp, routers, systems of the isp, etc.)OTHEROut of Scope19:08
Addedplease note that some of the applications may contain links or redirect you away from the uris described in the scope section. this means you are leaving the scope if you follow these links / redirectsOTHEROut of Scope19:08
Addedhttps://account.post.chURLIn Scope19:08
Addedhttps://service.post.ch/ekp-webURLIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=com.nth.swisspost&hl=de_CH&gl=USANDROIDIn Scope19:08
Addedhttps://itunes.apple.com/ch/app/postcard-creator/id820354055?mt=8IOSIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedthe alternative login (https://login.swissid.ch) is out of scope. it also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scopeOTHEROut of Scope00:51
Addedhttps://service.post.ch/ekp-webURLIn Scope00:51
Addedhttps://play.google.com/store/apps/details?id=com.nth.swisspost&hl=de_CH&gl=USANDROIDIn Scope00:51
Addedhttps://itunes.apple.com/ch/app/postcard-creator/id820354055?mt=8IOSIn Scope00:51
Addedplease note that some of the applications may contain links or redirect you away from the uris described in the scope section. this means you are leaving the scope if you follow these links / redirectsOTHEROut of Scope00:51
Addedhttps://account.post.chURLIn Scope00:51
Addedhttps://apps.apple.com/ch/app/die-post/id378676700IOSIn Scope00:51
Addedhttps://play.google.com/store/apps/details?id=ch.post.it.pcc&hl=enANDROIDIn Scope00:51
Added(*.post.ch:80|*.post.ch:443) and 194.41.128.0/17WILDCARDIn Scope00:51
Added(*.post.ch:80|*.post.ch:443) and 194.41.128.0/17WILDCARDIn Scope00:51
Addedhttps://shop.post.ch/shopURLIn Scope00:51
Addedhttps://service.post.ch/zopa/appURLIn Scope00:51
Addedhttps://service.post.ch/ele-klp/eleURLIn Scope00:51
Addedattacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes dns, ntp, routers, systems of the isp, etc.)OTHEROut of Scope00:51
Addedhttps://billingonline.post.ch/OnlinePayment/Web/v1/BOIURLIn Scope00:51
Addedanything that has not been described as in scope in the previous section is automatically out of scopeOTHEROut of Scope00:51
Addedany services related to incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHEROut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed(*.post.ch:80|*.post.ch:443) and 194.41.128.0/17OTHERIn Scope21:40
Removedhttps://account.post.chURLIn Scope21:40
Removedhttps://shop.post.ch/shopURLIn Scope21:40
Removedhttps://service.post.ch/ekp-webURLIn Scope21:40
Removedhttps://service.post.ch/zopa/appURLIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=com.nth.swisspost&hl=de_CH&gl=USANDROIDIn Scope21:40
Removedhttps://apps.apple.com/ch/app/die-post/id378676700IOSIn Scope21:40
Removedhttps://itunes.apple.com/ch/app/postcard-creator/id820354055?mt=8IOSIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=ch.post.it.pcc&hl=enANDROIDIn Scope21:40
Removedhttps://billingonline.post.ch/OnlinePayment/Web/v1/BOIURLIn Scope21:40
Removedhttps://service.post.ch/ele-klp/eleURLIn Scope21:40
Removedanything that has not been described as in scope in the previous section is automatically out of scopeOTHEROut of Scope21:40
Removedattacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes dns, ntp, routers, systems of the isp, etc.)OTHEROut of Scope21:40
Removedthe alternative login (https://login.swissid.ch) is out of scope. it also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scopeOTHEROut of Scope21:40
Removedany services related to incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHEROut of Scope21:40
Removedplease note that some of the applications may contain links or redirect you away from the uris described in the scope section. this means you are leaving the scope if you follow these links / redirectsOTHEROut of Scope21:40
Addedattacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes dns, ntp, routers, systems of the isp, etc.)OTHEROut of Scope00:33
Addedthe alternative login (https://login.swissid.ch) is out of scope. it also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scopeOTHEROut of Scope00:33
Addedany services related to incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHEROut of Scope00:33
Addedplease note that some of the applications may contain links or redirect you away from the uris described in the scope section. this means you are leaving the scope if you follow these links / redirectsOTHEROut of Scope00:33
Addedanything that has not been described as in scope in the previous section is automatically out of scopeOTHEROut of Scope00:33