Insurance Australia Group · Vulnerability Disclosure

Iag Vulnerability Disclosure

Vulnerability disclosure

Insurance Australia Group runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

InsuranceAustraliaNew ZealandProperty and CasualtyGeneral InsuranceCarrierUnderwritingClaimsBrokerPartner Gated
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:cybersecurity@iag.com.au

Source

Vulnerability Disclosure

iag-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
summary: >-
  Insurance Australia Group operates a HackerOne vulnerability disclosure
  programme at https://hackerone.com/iag. Ownership was confirmed directly
  against HackerOne's own public GraphQL endpoint, which resolves the team
  handle "iag" to name "Insurance Australia Group" with website
  http://iag.com.au — this disambiguates it from International Airlines Group
  and from AIG (hackerone.com/aig), both of which run separate programmes. It is
  a disclosure policy rather than a paid bounty: the group's own security.txt,
  published until mid-2025, stated "No paid bounties currently offered".
policy:
- https://hackerone.com/iag
contact:
- mailto:cybersecurity@iag.com.au
program:
  platform: HackerOne
  handle: iag
  url: https://hackerone.com/iag
  owner: Insurance Australia Group
  owner_website: http://iag.com.au
  type: vulnerability-disclosure-policy
  paid_bounties: false
  bounty_evidence: >-
    "Policy: No paid bounties currently offered" — group security.txt, last
    published revision 2025-04-01.
evidence:
- source: https://hackerone.com/graphql
  kind: platform-api
  query: 'query { team(handle: "iag") { handle name website } }'
  result: '{"handle":"iag","name":"Insurance Australia Group","website":"http://iag.com.au"}'
  note: Authoritative first-party confirmation of programme ownership.
- source: https://hackerone.com/iag
  kind: disclosure-page
  title: Insurance Australia Group | Vulnerability Disclosure Policy
  note: >-
    Page is a client-rendered SPA, so the policy body is not retrievable
    anonymously; the title and the GraphQL record are the recorded evidence.
- source: well-known/iag-security.txt
  kind: security.txt
  note: >-
    RFC 9116 document served on iag.com.au and six brand domains until mid-2025.
    Carries Contact, Preferred-Languages, Canonical, Policy and Hiring fields.
    Withdrawn — see well-known/iag-well-known.yml for the timeline.
gaps:
- No live /.well-known/security.txt on any IAG host as of 2026-07-25.
- No responsible-disclosure page on the corporate website; the Akamai edge
  returns 403 to non-browser clients for every path below the document root.
- security.iag.com.au exists but returns HTTP 401 behind an IBM Verify Identity
  Access for Web basic-auth realm — an internal surface, not a disclosure page.