Porsche Bug Bounty 2025
High-tech

Porsche Bug Bounty 2025

Porsche Bug Bounty: What the brand actually announced in 2025

Sports Cup Modern Villa

A Porsche is judged by the precision of its trajectory, the quality of its assembly, and that instantly recognizable mechanical feel. Now, it is also judged by what is unseen: the robustness of an application, the protection of a customer account, the reliability of a connected service, or the security of the data that flows between the vehicle and the brand's digital infrastructure.

On August 13, 2025, Porsche officially launched the third round of its vulnerability hunting program. It was scheduled to begin on August 18, 2025, following a pilot program in 2023 and a second four-week operation in 2024. The objective of the Porsche Bug Bounty is simple in principle, but strategic in its execution: to invite ethical hackers to search for vulnerabilities in specifically authorized digital assets before they can be exploited by malicious actors.

The program is not a standalone public relations exercise. Porsche presents it as a complementary measure to the activities of its global cybersecurity team. External researchers operate within a defined framework, on selected assets, and according to specific rules.

In its press release of August 13, 2025, the brand stated that several hundred cybersecurity specialists participated in the various operations organized over the previous two years. Their reports reportedly helped improve information security and provide a better understanding of certain potential attack methods and surfaces.

The main innovation of the third cycle lies in the integration of artificial intelligence tools into the report review process. Porsche explains that this assistance should improve both the speed and quality of the analysis of reports submitted by researchers.

The goal is not to replacehuman expertise, but to facilitate initial classification,duplicate identification , and prioritization of a potentially large volume of reports. For a manufacturer whose digital services are constantly evolving, reducing the time between vulnerability discovery, assessment, and remediation is a major challenge.

A ramp-up that began in 2023

Official dateProgram stageStrategic evolution
October 31, 2023Pilot project announcementFirst structured collaboration with external researchers
November 12, 2024Launch of a four-week editionMore than 200 participants in the previous pilot program and a desire to renew the program
August 13, 2025Announcement of the third cycleGradual expansion of the system and integration of AI into the review of reports
August 18, 2025The third cycle has been announced as opening dayNew phase of structured research on authorized assets
August 5, 2026HackerOne public page statusThe platform currently indicates that Porsche is not accepting new submissions

The 2023 pilot edition had already brought together more than 200 qualified researchers worldwide. Following this result, Porsche announced in November 2024 its intention to regularly organize Bug Bounty programs aimed at strengthening the security of its products and digital services.

The HackerOne page consulted when this article was updated specifies, however, that Porsche is not currently accepting new submissions. Therefore, the device, launched in August 2025, should not be interpreted as a program that is necessarily permanently open. Researchers should always verify its status and scope before conducting any tests.

How does the Porsche program work on HackerOne?

A bug bounty program is a structured program in which an organization allows researchers to test certain elements of its digital environment. When a valid vulnerability is discovered and properly documented, a financial reward may be paid.

At Porsche, the public framework is based on several essential principles.

1. A precisely defined search scope

Researchers do not have blanket authorization to test the entire Porsche ecosystem. They must limit themselves to the domains, applications, or services explicitly mentioned in the published scope.

Testing an asset outside the scope of the agreement remains prohibited. HackerOne specifies that only vulnerabilities discovered under the Safe Harbor can be examined for reward purposes.

This nuance is important: the existence of a Porsche program on HackerOne does not constitute permission to freely test a vehicle, a dealership, an industrial infrastructure or any domain using the brand name.

2. Research conducted by ethical hackers

Participants are looking for configuration errors, application flaws, access control problems, or vulnerabilities that could expose sensitive data or functions.

Their approach must remain measured, reproducible, and compliant with the program rules. Destructive testing, deliberate service interruptions, or unnecessarily accessed personal data may be prohibited, even when carried out with the intention of demonstrating a vulnerability.

3. A reproducible technical report

A discovery is not enough. The researcher must explain:

  • the asset in question;
  • the conditions necessary for operation;
  • the stages of reproduction;
  • the potential impact;
  • the elements allowing the Porsche team to confirm the problem;
  • possible risk reduction measures.

The quality of the report is crucial. A clearly demonstrated scenario can be analyzed more quickly than an imprecise alert or an automatically generated result without validation.

4. A classification based on severity

Thesecurity team then verifies whether the vulnerability is real, reproducible, new, and located within the permitted scope. Its severity is assessed based on its technical impact, ease of exploitation, and potential consequences for users or the organization. The public scale currently indexed on HackerOne displays the following amounts:

SeverityDisplayed reward
Weak$50 to $150
Average$300 to $600
High$700 to $1,500
Critical$2,000 to $5,000

These amounts may change. They do not constitute automatic compensation: the report must be valid, original, compliant with the rules, and eligible for the program.

5. A correction integrated into the product cycle

Once the vulnerability is confirmed, it can be reported to the teams responsible for the affected asset. The fix must then be developed, tested, and deployed without introducing new instability.

This is where Bug Bounty becomes truly valuable. It's not just about accumulating reports, but about transforming each relevant discovery into a concrete improvement: a new development rule, additional control, better monitoring, or a reduction in the attack surface.

Why is cybersecurity becoming strategic for Porsche?

Inpremium automobiles, technology has long been presented as an added comfort feature. It now constitutes the invisible architecture of the experience.

Customer account, mobile application, navigation, maintenance, charging, personalization, remote services, and connected features make up an environment in which the vehicle interacts with multiple platforms. As this environment becomes more complex, the possibilities for interaction increase, but so do the areas requiring attention.

This evolution is particularly visible in the luxury electric vehicle sector, where software, charging, and digital services directly contribute to the perception of quality. Sophistication is no longer limited to materials or power; it is also measured by the fluidity and reliability of the ecosystem.

For Porsche, automotive cybersecurity therefore addresses several imperatives.

Preserve the continuity of the experience

A premium customer expects a seamless experience. An unavailable app, faulty authentication, or inconsistent digital service can negatively impact the overall perception of the vehicle, even when its mechanical qualities remain intact.

In the luxury sector, every digital friction becomes a brand friction.

Protecting particularly sensitive data

Connected vehicles can process information related to location, movement, usage patterns, or interactions with different services.

On June 30, 2026, the CNIL (French Data Protection Authority) reiterated that vehicle location data is highly personal. It can reveal users' movements, frequented locations, and certain interests. The French authority emphasizes, in particular, the importance of transparency, data minimization, data retention periods, and data security.

Protecting this information goes beyond mere regulatory compliance. It becomes a component of the relationship of trust, just like the confidentiality of a private lounge or the discretion of a concierge service.

This dimension is more broadly linked to the challenges of customer relations in the luxury sector in the age of artificial intelligence : the more a brand personalizes its experience, the more it must demonstrate its ability to govern and protect the information that makes it possible.

Maintaining brand value

A luxury brand controls its image, its materials, its spaces, and its public statements. It must now also control its digital dependencies.

Trust is not based on the assertion that no flaws exist. No complex system can reasonably offer such a guarantee. It is based on the ability to organize the search, the reporting, the correction, and the learning.

Bug Bounty thus transforms a form of theoretical vulnerability into an operational discipline: the brand accepts that a defect may be discovered, but refuses to let it be ignored.

Bug bounty, penetration testing and auditing: complementary approaches

A Bug Bounty program does not replace security audits, code reviews, or penetration tests performed by specialized providers.

Penetration testing is generally conducted over a specific period, with an identified team and a defined scenario. It provides a structured and in-depth analysis of a given scope.

Bug bounty programs introduce a different logic: a larger community can mobilize diverse skills, habits, and methods. This diversity increases the chances of discovering unexpected scenarios, particularly on services that are constantly exposed and regularly updated.

The two models therefore meet distinct needs:

  • The pentesting provides an expert snapshot at a given moment;
  • The audit verifies the organization, processes, or compliance;
  • The code review analyzes the technical design;
  • Bug Bounty adds an external and diversified research capability;
  • The monitoring system detects exploitation attempts in real-world conditions.

Maturity is not about choosing a single method, but about articulating these different levels of defense.

What Porsche earns from ethical hackers

Earlier detection

The earlier a vulnerability is identified, the sooner the company can fix it before it is exploited or incorporated into other attack scenarios.

A diversity of methods

Two researchers do not necessarily approach an application in the same way. Some specialize in access controls, others in programming interfaces, cloud configurations, or complex operating chains.

This diversity is one of the main strengths of an international community.

A better understanding of attack surfaces

A relevant report does not simply show that a weakness exists. It sometimes reveals a poorly understood dependency, an unforeseen usage logic, or a combination of functions that was not considered during the design phase.

Continuous improvement

Each validated vulnerability can enrich future controls: development rules, automated tests, threat models, internal training or validation procedures.

A more credible signal of trust

Openness to external researchers does not prove that an ecosystem is invulnerable. It shows that an organization accepts technical contradictions and creates a channel to address them.

In the world of luxury, this stance matters. Discretion is not silence in the face of risk; it is the ability to manage it without compromising the experience.

Does Bug Bounty actually change anything for the customer?

The owner of a Porsche doesn't directly see the work of researchers. He mainly perceives the indirect consequences:

  • more resilient services;
  • better account protection;
  • a reduction in the risk of data exposure;
  • faster correction processes;
  • a more stable digital experience;
  • a brand better prepared for new threats.

This invisible security perfectly aligns with contemporary luxury codes. A high-end service doesn't flaunt its complexity; it absorbs difficulties before they reach the client.

The same principle applies to traceability, authenticity, and digital passports in the luxury sector. Trust no longer depends solely on the physical object. It depends on all the information, platforms, and services that accompany it.

Why is the Porsche program also an image issue?

The Bug Bounty program is contributing to the transformation of the car manufacturer into a digital services company.

Porsche remains associated with engineering, design, and performance. But its brand territory now includes applications, accounts, data, cloud infrastructure, and remote interactions. The perceived quality of this environment must remain consistent with that of the vehicle.

This issue is all the more sensitive given that Porsche has an international, mobile, and tech-savvy customer base. A digital weakness could affect not only a service, but also the personal relationship the brand maintains with its customers.

By displaying a structured approach, Porsche is therefore trying to make IT security an extension of its engineering culture: observe, test, correct and repeat.

This evolution can be followed in all the Porsche news published by Luxe Daily, which shows how the brand seeks to reconcile sporting heritage, electrification, services and new uses.

Update 2026: Is the Porsche program still open?

As of August 5, 2026, the public HackerOne page indicates that Porsche is not currently accepting new submissions. This does not invalidate the third round launched in August 2025. It simply means that the programs may operate through successive campaigns, open periods, or scopes.

Researchers wishing to participate must consult the current policy before each test. Status, permitted assets, exclusions, and rewards are subject to change.

This timeframe also highlights a crucial point: a Bug Bounty is not a permanent research permit. It is an operational contract whose limits must be strictly adhered to.

FAQ about the Porsche Bug Bounty

What is the Porsche Bug Bounty?

The Porsche Bug Bounty program allows cybersecurity researchers to report vulnerabilities discovered in explicitly authorized digital assets. Valid and eligible reports may result in a financial reward.

When did the third cycle begin?

Porsche announced the third cycle on August 13, 2025 and indicated that it would be open from August 18, 2025.

When was the first Porsche program launched?

The pilot project was announced on October 31, 2023.More than 200 international researchers participated in this first phase, according to Porsche.

How much does Porsche pay for a vulnerability?

The public grid indexed on HackerOne displays rewards ranging from $50 for some minor vulnerabilities to $5,000 for critical discoveries. The amount depends on the severity, impact, and eligibility of the report.

Can you test drive a Porsche car directly?

Not without explicit authorization. Researchers must limit themselves to assets listed within the scope of the program. The existence of a Bug Bounty program does not grant any general permission to test a vehicle, an embedded system, a dealership, or the brand's infrastructure.

What is the purpose of the Safe Harbor Policy?

The Safe Harbor Policy defines the conditions under which good-faith research can be authorized. It protects the framework for cooperation, provided that the researcher strictly adheres to the scope, accepted methods, and disclosure rules.

Why use HackerOne?

HackerOne centralizes the publication of the scope, reports, exchanges between researchers and security teams, vulnerability assessment, and rewards. The platform thus facilitates structured collaboration with an international community.

Is the program open in August 2026?

The public page currently indicates that Porsche is not accepting new submissions. The status should be verified directly on HackerOne before any search.

Key points to remember

The third cycle of the Porsche Bug Bounty, announced on August 13 and launched on August 18, 2025, confirms that cybersecurity is no longer a peripheral function in luxury automobiles.

It protects the services, accounts, and data that now extend the vehicle experience. It also contributes to the brand's value: a value based on performance, but also on continuity, confidentiality, and technological expertise.

By mobilizing ethical hackers, Porsche isn't promising a vulnerability-free world. Rather, the brand is affirming its commitment to identifying, classifying, and correcting vulnerabilities before they escalate into incidents.

In connected automotive luxury, this ability to anticipate is perhaps the most contemporary form of quality: an invisible excellence, constantly tested and never taken for granted.

Official primary sources on the Porsche program

3 official French sources

  1. CNIL – Recommendation on the use of location data from connected vehicles, June 30, 2026
  2. ANSSI – Declaration and disclosure of vulnerabilities
  3. Cerema – Cybersecurity and secure architecture of connected vehicles