M-Pesa (Safaricom Daraja) · Vulnerability Disclosure

Mpesa Vulnerability Disclosure

Vulnerability disclosure

M-Pesa (Safaricom Daraja) runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Mobile MoneyPaymentsFintechKenyaAfricaM-Pesa
Program: Hackerone

Disclosure Policy

Security Contact

Contact
https://hackerone.com/safaricom
Contact
mailto:bugbounty@safaricom.co.ke

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-17'
method: searched
probe: true
source: https://hackerone.com/safaricom
contact:
- https://hackerone.com/safaricom
- mailto:bugbounty@safaricom.co.ke
evidence:
- source: https://hackerone.com/safaricom
  kind: HackerOne vulnerability disclosure policy
  note: >-
    Safaricom runs a HackerOne Vulnerability Disclosure Program. Reports are submitted
    through the HackerOne portal (bugbounty@safaricom.co.ke referenced for intake);
    public disclosure is not permitted, and high-impact researchers may be invited to a
    private bug bounty. No dedicated /.well-known/security.txt was found on
    safaricom.co.ke (301) or developer.safaricom.co.ke (404) on the probe date.