Liberty Global · Vulnerability Disclosure

Liberty Global Vulnerability Disclosure

Vulnerability disclosure

Liberty Global runs a coordinated vulnerability disclosure program on Hackerone.

TelecommunicationsUnited KingdomBroadbandFixed BroadbandMobile Network OperatorNetwork APIsCAMARAOpen Gateway5GEuropeSet-Top BoxRDK
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
published: false
summary: >-
  Liberty Global publishes no vulnerability disclosure policy. No security.txt,
  no responsible-disclosure page, no security contact address, no bug bounty
  programme it operates. The only artifact that exists is an unclaimed
  third-party directory entry on HackerOne, recorded below because it is easily
  mistaken for a programme. No `Security` pointer is wired into apis.yml —
  there is no policy URL to point at.
policy: []
contact: []
security_txt:
  published: false
  note: >-
    /.well-known/security.txt and /security.txt both return 404 on
    www.libertyglobal.com, the only first-party host that resolves. See
    well-known/liberty-global-well-known.yml.
external_listing:
  platform: HackerOne
  url: https://hackerone.com/libertyglobal
  program_id: 5947
  program_name: Liberty Global Ventures
  is_external_program: true
  claimed: false
  offers_rewards: false
  policy: null
  policy_url: null
  disclosure_email: ''
  disclosure_url: ''
  scopes: [libertyglobal.com, liberty.com]
  fetched: '2026-07-25'
  http_status: 200
  assessment: >-
    This is a HackerOne *external* directory record, not a Liberty Global
    programme. HackerOne's own JSON marks it is_external_program: true and
    claimed: false, with a null policy, an empty disclosure email and an empty
    disclosure URL. Nobody at Liberty Global has claimed it and there is no
    published brief a researcher could follow. It is a listing, not a front
    door — and it is named after Liberty Global Ventures, the investment arm,
    not the operating group. Recorded as evidence, not counted as a disclosure
    programme.
probed:
- {url: 'https://www.libertyglobal.com/.well-known/security.txt', status: 404}
- {url: 'https://www.libertyglobal.com/security.txt', status: 404}
- {url: 'https://www.libertyglobal.com/security/', status: 404}
- {url: 'https://www.libertyglobal.com/responsible-disclosure/', status: 404}
- {url: 'https://www.libertyglobal.com/vulnerability-disclosure/', status: 404}
- {url: 'https://www.libertyglobal.com/report-a-vulnerability/', status: 404}
- {url: 'https://www.libertyglobal.com/about/corporate-governance/responsible-disclosure/', status: 404}
- {url: 'https://bugcrowd.com/libertyglobal', status: 404}
- {url: 'https://security.libertyglobal.com', status: DNS NXDOMAIN}
- {url: 'https://trust.libertyglobal.com', status: DNS NXDOMAIN}
adjacent_evidence:
- source: https://www.libertyglobal.com/about/corporate-governance/data-privacy-protection/
  kind: corporate-security-governance-page
  fetched: '2026-07-25'
  http_status: 200
  detail: >-
    Names GDPR, the Sarbanes-Oxley Act, ISO 27001, CAS(T) and PCI DSS, and
    describes a "Digital Confidence" team overseeing privacy, lawful intercept
    and security. It does not reference a vulnerability disclosure process or
    publish a security contact. Captured in
    conformance/liberty-global-conformance.yml.
- source: https://www.libertyglobal.com/careers/vacancy/business-information-security-officer-req_00037975/
  kind: job-posting
  fetched: '2026-07-25'
  detail: >-
    A live Business Information Security Officer vacancy, and a cybersecurity
    graduate scheme, confirm a real internal security function exists. It has
    no public reporting channel.
note_for_researchers: >-
  A researcher who finds a flaw in a Liberty Global property has no documented
  route to report it to the parent. The practical channels are the operating
  companies' own programmes (Virgin Media O2, VodafoneZiggo, Telenet) or the
  developers@libertyglobal.com address advertised on the LibertyGlobal GitHub
  organisation profile — which sits alongside a blog URL,
  https://developer.libertyglobal.com, that is NXDOMAIN, so its liveness is
  unverified.