Program Overview
Equifax-vdp runs a vulnerability disclosure program on HackerOne. The program has 282 in-scope assets and is managed by HackerOne's triage team.
In-Scope Assets
| Asset | Type | Max Severity | Eligible |
|---|---|---|---|
| *.abr.com.au | WILDCARD | Critical | No Bounty |
| *.accountscore.co.uk | OTHER | Critical | No Bounty |
| *.accountscore.com | OTHER | Critical | No Bounty |
| *.accountscore.net | OTHER | Critical | No Bounty |
| *.ansoniacreditdata.com | OTHER | Critical | No Bounty |
| *.appriss.com,*.appriss.net,*.apprissafety.com,*.apprissgomobile.com,*.apprissinsights.com,*.apprissinsights.net,*.apprissmobile.com | OTHER | Critical | No Bounty |
| *.boavistascpc.com.br | WILDCARD | Critical | No Bounty |
| *.boavistaservicos.com.br | WILDCARD | Critical | No Bounty |
| *.bvsnet.com.br | WILDCARD | Critical | No Bounty |
| *.certificadoboavista.com.br | WILDCARD | Critical | No Bounty |
| *.datacredito.com | OTHER | Critical | No Bounty |
| *.datacredito.com.do | OTHER | Critical | No Bounty |
| *.datacredito.info | OTHER | Critical | No Bounty |
| *.datacredito1.com | OTHER | Critical | No Bounty |
| *.datacredito2.com | OTHER | Critical | No Bounty |
| *.datacredito3.com | OTHER | Critical | No Bounty |
| *.decisionpoint3.com | WILDCARD | Critical | No Bounty |
| *.dicom.cl | OTHER | Critical | No Bounty |
| *.efficientforms.com | OTHER | Critical | No Bounty |
| *.efficienthire.com | OTHER | Critical | No Bounty |
| *.employersedge.com | OTHER | Critical | No Bounty |
| *.employersedge.net | OTHER | Critical | No Bounty |
| *.equifax.cl | OTHER | Critical | No Bounty |
| *.equifax.com | OTHER | Critical | No Bounty |
| *.equifax.com.pe | OTHER | Critical | No Bounty |
| *.equifax.cr | WILDCARD | Critical | No Bounty |
| *.fraudday.com | WILDCARD | Critical | No Bounty |
| *.healthefx.net | OTHER | Critical | No Bounty |
| *.healthefx.us | OTHER | Critical | No Bounty |
| *.healthefxforms.us | OTHER | Critical | No Bounty |
| *.hiretech.com | OTHER | Critical | No Bounty |
| *.i2verify.com | OTHER | Critical | No Bounty |
| *.i9advantage.com | OTHER | Critical | No Bounty |
| *.i9anywhere.com | OTHER | Critical | No Bounty |
| *.idwatchdog.com | WILDCARD | Critical | No Bounty |
| *.konduto.blog | WILDCARD | Critical | No Bounty |
| *.konduto.com | WILDCARD | Critical | No Bounty |
| *.kount.com | OTHER | Critical | No Bounty |
| *.kount.net | OTHER | Critical | No Bounty |
| *.mapcity.com | OTHER | Critical | No Bounty |
| *.mercury.com.au | WILDCARD | Critical | No Bounty |
| *.midigator.com | OTHER | Critical | No Bounty |
| *.ntcusa.com | WILDCARD | Critical | No Bounty |
| *.paynet.us,*.paynet.ca,*.paynet.com,*.paynet.credit | OTHER | Critical | No Bounty |
| *.paynetonline.us,*.paynetonline.ca,*.paynetonline.com,*.paynetonline.site,*.paynetonline.mobi | OTHER | Critical | No Bounty |
| *.redeverdeamarela.com.br | WILDCARD | Critical | No Bounty |
| *.scpcnet.com.br | WILDCARD | Critical | No Bounty |
| *.talx.com | OTHER | Critical | No Bounty |
| *.vineapps.com | WILDCARD | Critical | No Bounty |
| *equifax.ca | OTHER | Critical | No Bounty |
Showing 50 of 282 in-scope assets. View all on HackerOne.
Out-of-Scope Assets
- *.acordocerto.com.br
- preview.midigator.com
Tips for Hacking Equifax-vdp
- Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
- Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
- Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
- Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
- Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.
Frequently Asked Questions
How do I start hacking Equifax-vdp?
Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.
Does Equifax-vdp pay bounties?
No, Equifax-vdp runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.
What types of vulnerabilities does Equifax-vdp accept?
Equifax-vdp accepts reports for vulnerabilities found in their 282 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.