I emailed Agoda's security contact on June 18 and heard nothing for 28 days. Now their security.txt points to HackerOne, and my report there was closed as a duplicate
A security researcher reported a vulnerability on Agoda's main domain following the instructions in Agoda's security.txt file, which at the time listed an email contact. The researcher received no acknowledgment for 28 days. Later, Agoda's security.txt was updated to point to a HackerOne bug bounty program, where the report was closed as a duplicate of an earlier submission. The researcher experienced unclear guidance from HackerOne about reporting issues on domain paths outside the program's listed scope, leading to confusion and delayed remediation.
AI Analysis
Technical Summary
The researcher discovered a vulnerability on Agoda's main domain in June 2026. Agoda's security.txt file then listed an email address for vulnerability reports, which the researcher used but received no response. HackerOne's support did not clarify whether out-of-scope domain paths could be reported through their platform. After waiting 28 days with no acknowledgment from Agoda's email contact, the researcher submitted the report via HackerOne, where it was closed as a duplicate of an earlier report. Agoda's security.txt was later updated to direct reporters to HackerOne, but the timing and reason for this change are unclear. The incident highlights issues in vulnerability disclosure processes and communication channels rather than a specific technical vulnerability.
Potential Impact
The impact is procedural and operational rather than technical. A valid security issue remained unaddressed for at least 28 days due to unclear reporting channels and lack of acknowledgment from Agoda's security contact. This delay could have prolonged exposure to the vulnerability on a major travel booking site. However, the issue was eventually acknowledged and is being addressed through the HackerOne program.
Mitigation Recommendations
No direct technical mitigation is described or required from the researcher's perspective. The vendor has updated their security.txt to point to the HackerOne program, which suggests they are consolidating vulnerability reports through that platform. Researchers should follow the updated security.txt instructions. Vendors should ensure clear, responsive communication channels for vulnerability disclosures, including guidance on out-of-scope assets within the same domain.
I emailed Agoda's security contact on June 18 and heard nothing for 28 days. Now their security.txt points to HackerOne, and my report there was closed as a duplicate
Description
A security researcher reported a vulnerability on Agoda's main domain following the instructions in Agoda's security.txt file, which at the time listed an email contact. The researcher received no acknowledgment for 28 days. Later, Agoda's security.txt was updated to point to a HackerOne bug bounty program, where the report was closed as a duplicate of an earlier submission. The researcher experienced unclear guidance from HackerOne about reporting issues on domain paths outside the program's listed scope, leading to confusion and delayed remediation.
Reddit Discussion
I do bug bounty hunting and I want to share how a simple responsible disclosure turned into a mess. Two different channels failed me here, and I think both are worth talking about.
In June I found a vulnerability on Agoda's main domain. Agoda has a public HackerOne program, but only one specific path is listed as in scope, and what I found was on a different part of the same domain. I wasn't sure if I was allowed to submit it there.
I didn't want to break any rules, so I opened a ticket with HackerOne Support and asked two simple questions. Can I submit a bug on the same domain if the path isn't listed in scope? And if not, should I report it directly to Agoda's security contact instead?
The reply didn't really answer either one. It told me to avoid reaching out to the program directly and to not work on out of scope assets, because reports marked as spam or not applicable can hurt my signal and reputation. That was it. No "yes, submit it", no "no, email them", nothing about what to do with a real bug that sits on the same domain but outside the listed path. The ticket was then closed.
So the platform's guidance boiled down to "don't touch it" with no word on where it should go.
The only other place to look was Agoda's own security.txt. When I checked in June, the Contact line was an email address, [[email protected]](mailto:[email protected]), with no mention of HackerOne. I didn't take a screenshot at the time, which was my mistake, so the best I can offer is this archived copy from February 2026 showing the same setup: https://web.archive.org/web/20260206144235/agoda.com/security.txt
On June 18 I sent a full, detailed report to that address. Clear steps, clear impact, everything a security team would need.
Nothing came back. No auto reply, no acknowledgement, nothing.
On June 21 I tagged Agoda on X and asked them to check their inbox. Their public reply was a generic line about following the account so they could DM me my "booking details", which had nothing to do with a security report. I DMed them anyway, and the rep told me to be patient while the relevant team reviews it and that response times vary. Fair enough, so I waited.
I waited 28 days. Still no acknowledgement from the security email, and the issue was still live. So on July 16 I submitted it through HackerOne, since it was the only way I could think of to get it in front of someone who would actually read it.
It was closed as a duplicate within a few hours. The original report was filed on June 29, which is 11 days after I emailed their official security contact. HackerOne's triage also told me the program has already acknowledged the issue and is working on it through that original report.
Here's the part that bothers me most. If you open Agoda's security.txt today, the Contact line no longer lists that email. It now points to their HackerOne report form, and there's a Policy line pointing to the program page. I don't know exactly when it changed or why. My guess, and it is only a guess, is that it was updated some time after the other researcher's report came in, but I can't prove that. What I do know is that in June the published instruction was to email an address that, as far as I can tell, nobody was answering, and I did exactly what the file told me to do.
So either my email was never read, or it was read and nothing happened with it. Either way, a valid issue was sitting on a major travel booking site, and the only reason anyone is working on it is that someone else happened to use a different route.
I'm not complaining about the duplicate. Dupes happen and I get it. My problem is the system around it. HackerOne gave me no usable guidance on same domain assets outside the listed scope, and Agoda's published security inbox went nowhere. I tried to follow the rules at every step and ended up with nothing.
I'm keeping all technical details out of this post on purpose, because I don't want to put users at risk. I have the original email, the HackerOne support ticket, the X conversation and the duplicate notice saved with timestamps if anyone needs proof.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The researcher discovered a vulnerability on Agoda's main domain in June 2026. Agoda's security.txt file then listed an email address for vulnerability reports, which the researcher used but received no response. HackerOne's support did not clarify whether out-of-scope domain paths could be reported through their platform. After waiting 28 days with no acknowledgment from Agoda's email contact, the researcher submitted the report via HackerOne, where it was closed as a duplicate of an earlier report. Agoda's security.txt was later updated to direct reporters to HackerOne, but the timing and reason for this change are unclear. The incident highlights issues in vulnerability disclosure processes and communication channels rather than a specific technical vulnerability.
Potential Impact
The impact is procedural and operational rather than technical. A valid security issue remained unaddressed for at least 28 days due to unclear reporting channels and lack of acknowledgment from Agoda's security contact. This delay could have prolonged exposure to the vulnerability on a major travel booking site. However, the issue was eventually acknowledged and is being addressed through the HackerOne program.
Defensive Guidance
No direct technical mitigation is described or required from the researcher's perspective. The vendor has updated their security.txt to point to the HackerOne program, which suggests they are consolidating vulnerability reports through that platform. Researchers should follow the updated security.txt instructions. Vendors should ensure clear, responsive communication channels for vulnerability disclosures, including guidance on out-of-scope assets within the same domain.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- false
- Trusted Domain
- false
Threat ID: 6abe75ada43b0b3b89bd9c4b
Added to database: 10/01/2026, 15:01:01 UTC
Last enriched: 10/01/2026, 15:01:07 UTC
Last updated: 10/01/2026, 16:15:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.