UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉
Наталя ХандусенкоHot News
17 June 2025, 18:04
2025-06-17
COMFY paid 200,000 UAH to a white hat hacker for discovering a critical vulnerability
COMFY became one of the first Ukrainian retailers to publicly support ethical hacking in practice. The company made an official payment of UAH 200,000 to white hat hacker Vadym Savchenko. He reported a critical vulnerability in the online store's bonus accrual system.
COMFY became one of the first Ukrainian retailers to publicly support ethical hacking in practice. The company made an official payment of UAH 200,000 to white hat hacker Vadym Savchenko. He reported a critical vulnerability in the online store's bonus accrual system.
Savchenko sent information about the problem through the contact center. It concerned the possibility of receiving bonuses multiple times as part of marketing activity, which created the risk of uncontrolled accumulation of funds in the bonus account.
After verification and technical testing, COMFY confirmed the vulnerability, assessed the potential damage in case of abuse, and promptly eliminated it. Internal monitoring systems did not record the anomaly, which revealed the need to improve control processes.
The company decided to pay UAH 200,000 as a reward for responsible disclosure. This is the first such case in COMFY's history and one of the few public examples of bug bounty payments in Ukrainian retail.
Vadym Savchenko has experience in IT and cybersecurity. In his communication with the company, he noted that he considers helping businesses prevent cyberattacks an important part of shared responsibility in wartime. It was for these reasons that he quickly contacted COMFY immediately after discovering the problem.
Back in 2018, COMFY publicly supported the ethical hacking movement: the company posted a special file on its server inviting security researchers to interact with it and identified channels for responsible vulnerability disclosure. The current story is a logical continuation of this practice.
Як показує практика, Українські компанії неохоче платять за знайдені вразливості, а тих хто платить- можна перелічити на пальцях однієї руки.
Швидше за все, Вас просто проігнорять.
Хоча з кожного правила є винятки...
Як показує практика, Українські компанії неохоче платять за знайдені вразливості, а тих хто платить- можна перелічити на пальцях однієї руки.
Швидше за все, Вас просто проігнорять.
Хоча з кожного правила є винятки...