
ING
External Program
Submit bugs directly to this organization
#Responsible Disclosure
Do you have the skills and did you discover any vulnerabilities in our systems? If so, help us by reporting these vulnerabilities. So that we can improve the safety and reliability of our systems together.
##ING and safety As ING we consider the safety of internet banking and the continuity of our online services as one of our top priorities. Every day and night, our specialists work on optimizing our systems and processes. Despite the effort we put into the security of our systems, vulnerabilities in our systems might still be present.
##What to report?
Vulnerabilities with regard to the safety of ING’s services offered through the internet. In case you have discovered a vulnerability in our system, please report this as quickly as possible. Examples of vulnerabilities could be:
##What is [email protected] not used for?
##How can a vulnerability be reported? A vulnerability can be reported by e-mail; [email protected]. A prerequisite for sending an e-mail to the above mentioned e-mail address is that you utilize the public PGP key (zip). Please ensure that your e-mail is written in a clear and succinctly way. Particularly include the following in your e-mail:
##Am I eligible for a reward after my finding? ING highly appreciates your effort by assisting us in optimizing our systems and processes. In case your reported vulnerabilities have been solved or led to a change in our services, you will be eligible for a reward.
##Can I report a vulnerability anonymously? Sure, you do not have to provide your name and contact details in case you want to report a vulnerability. However, you should take into account that we are unable to discuss the next steps with you. For instance, we cannot inform you about what we will do with your discovered vulnerability, neither we can collaborate further, nor we can provide you with the appropriate credits or reward in return for your finding.
##Your privacy Your personal information is only used to approach you and undertake actions with regard to your reported vulnerability. We will not distribute your personal information to third parties without your permission. Unless, the law requires us to provide your personal information or when an external organization takes over the investigation of your reported vulnerability. In this case we will ensure that the applicable authority will treat your personal information confidentially. We will remain responsible for your personal information.
##What will we do with your finding? A team of security experts will investigate your finding. Within two working days you will be receiving an e-mail with a first reply. Note: revealing your finding to the public is not allowed, instead talk to our experts and give them time to assess and solve the problem. Accordingly, we will provide you with feedback with regard to your finding. We will explain to you whether we will solve the problem, how we will solve it and when.
##Rules By investigating our IT systems, it might be that you act prosecutable. In case you act with good faith, act in accordance to the mentioned rules of the ING, there will not be any inducement to report your action. Therefore, follow the rules of the responsible disclosure.
##Remaining conditions
##Responsible Disclosure regulation With regard to reporting vulnerabilities in IT-systems, the National Cyber Security Centre of the Ministry of Security and Justice in the Netherlands has made up guidelines. ING’s guidelines are based upon those. In case you want to learn more about the guidelines made up by the Ministry of Security and Justice, visit: https://www.ncsc.nl/
##Aberrant international regulation We advise you to take into account that regulations with regard to the Responsible Disclosure differ per country. In case you are living abroad and have found vulnerabilities in one of our ING-pages, please realize that the Responsible Disclosure policy is not applicable in every country. This implies that despite you acted in accordance to ING’s Responsible Disclosure policy, it might still be that you will be prosecuted by justice, despite we do not report the vulnerability to justice.
##More info The US Federal Trade Commission provides information here on how to avoid phishing scams The Anti-Phishing Working Group provides statistics on phishing attacks and advice for individuals and companies.