Liberty Global · Vulnerability Disclosure
Liberty Global Vulnerability Disclosure
Vulnerability disclosure
Liberty Global runs a coordinated vulnerability disclosure program on Hackerone.
TelecommunicationsUnited KingdomBroadbandFixed BroadbandMobile Network OperatorNetwork APIsCAMARAOpen Gateway5GEuropeSet-Top BoxRDK
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-07-25'
method: searched
probe: true
published: false
summary: >-
Liberty Global publishes no vulnerability disclosure policy. No security.txt,
no responsible-disclosure page, no security contact address, no bug bounty
programme it operates. The only artifact that exists is an unclaimed
third-party directory entry on HackerOne, recorded below because it is easily
mistaken for a programme. No `Security` pointer is wired into apis.yml —
there is no policy URL to point at.
policy: []
contact: []
security_txt:
published: false
note: >-
/.well-known/security.txt and /security.txt both return 404 on
www.libertyglobal.com, the only first-party host that resolves. See
well-known/liberty-global-well-known.yml.
external_listing:
platform: HackerOne
url: https://hackerone.com/libertyglobal
program_id: 5947
program_name: Liberty Global Ventures
is_external_program: true
claimed: false
offers_rewards: false
policy: null
policy_url: null
disclosure_email: ''
disclosure_url: ''
scopes: [libertyglobal.com, liberty.com]
fetched: '2026-07-25'
http_status: 200
assessment: >-
This is a HackerOne *external* directory record, not a Liberty Global
programme. HackerOne's own JSON marks it is_external_program: true and
claimed: false, with a null policy, an empty disclosure email and an empty
disclosure URL. Nobody at Liberty Global has claimed it and there is no
published brief a researcher could follow. It is a listing, not a front
door — and it is named after Liberty Global Ventures, the investment arm,
not the operating group. Recorded as evidence, not counted as a disclosure
programme.
probed:
- {url: 'https://www.libertyglobal.com/.well-known/security.txt', status: 404}
- {url: 'https://www.libertyglobal.com/security.txt', status: 404}
- {url: 'https://www.libertyglobal.com/security/', status: 404}
- {url: 'https://www.libertyglobal.com/responsible-disclosure/', status: 404}
- {url: 'https://www.libertyglobal.com/vulnerability-disclosure/', status: 404}
- {url: 'https://www.libertyglobal.com/report-a-vulnerability/', status: 404}
- {url: 'https://www.libertyglobal.com/about/corporate-governance/responsible-disclosure/', status: 404}
- {url: 'https://bugcrowd.com/libertyglobal', status: 404}
- {url: 'https://security.libertyglobal.com', status: DNS NXDOMAIN}
- {url: 'https://trust.libertyglobal.com', status: DNS NXDOMAIN}
adjacent_evidence:
- source: https://www.libertyglobal.com/about/corporate-governance/data-privacy-protection/
kind: corporate-security-governance-page
fetched: '2026-07-25'
http_status: 200
detail: >-
Names GDPR, the Sarbanes-Oxley Act, ISO 27001, CAS(T) and PCI DSS, and
describes a "Digital Confidence" team overseeing privacy, lawful intercept
and security. It does not reference a vulnerability disclosure process or
publish a security contact. Captured in
conformance/liberty-global-conformance.yml.
- source: https://www.libertyglobal.com/careers/vacancy/business-information-security-officer-req_00037975/
kind: job-posting
fetched: '2026-07-25'
detail: >-
A live Business Information Security Officer vacancy, and a cybersecurity
graduate scheme, confirm a real internal security function exists. It has
no public reporting channel.
note_for_researchers: >-
A researcher who finds a flaw in a Liberty Global property has no documented
route to report it to the parent. The practical channels are the operating
companies' own programmes (Virgin Media O2, VodafoneZiggo, Telenet) or the
developers@libertyglobal.com address advertised on the LibertyGlobal GitHub
organisation profile — which sits alongside a blog URL,
https://developer.libertyglobal.com, that is NXDOMAIN, so its liveness is
unverified.