Purpose and Scope
This program incentivizes ethical collaboration to expand InsecureWeb’s dark web leaked data database. It offers rewards to organizations and verified cybersecurity professionals who submit publicly accessible leaked data (from dark web sources) containing sensitive information (credentials, PII, corporate data) that InsecureWeb can use to protect victims. The program is designed to adhere to U.S. laws and ethical guidelines, meaning no rewards for stolen data obtained via crime or to malicious actors. All contributed data must already be openly available on dark web forums or sites – no hacking or unauthorized access is permitted to obtain it . The goal is to responsibly collect breach data for defensive purposes, while avoiding any legal or ethical violations.
Eligibility Criteria
Only qualified, reputable participants are allowed, ensuring no bad actors abuse the program. Eligible contributors include:
- Cybersecurity Professionals – Individuals with verifiable credentials (e.g. security researchers, ethical hackers, threat intel analysts) who can prove their identity and expertise. Verification may involve ID checks, professional references, or industry certifications.
- Organizations and Trusted Teams – Companies (or their security teams) that sign up to contribute leaked data. An organization must designate an approved representative and undergo vetting.
- Good Faith Actors Only – Participants must attest that they are acting in good faith and did not personally cause the breach or steal the data. Those directly responsible for hacking or data theft are disqualified from rewards. (InsecureWeb will perform background checks to ensure a contributor is not a known malicious actor or on any sanctions list.)
- Agreement to Terms – All participants must sign the program’s agreement, affirming compliance with applicable laws (e.g. the U.S. Computer Fraud and Abuse Act) and program rules. This includes confirming that any data submitted was obtained through legal, ethical means and that the participant will maintain confidentiality and not misuse the data.
Ineligible parties: Anyone under 18 or in violation of U.S. law, the original attackers or data sellers, and any person or entity refusing to verify identity or agree to terms. InsecureWeb employees or contractors (and their immediate family) are typically ineligible to avoid conflicts of interest.
Qualifying Data for Submission
Not all data dumps are equal. To be rewarded, submissions must meet specific content and source criteria:
- Publicly Leaked on Dark Web: The data must be found on a public or semi-public dark web source – for example, posted on an open darknet forum, paste site, darknet marketplace, or a ransomware group’s leak site. It should be freely accessible (or accessible with general forum membership) without requiring the contributor to perform unauthorized intrusion. If the data came from a dark web marketplace or forum, the contributor should provide evidence that it was openly available (e.g. a URL or screenshot of the public post). This ensures the program only uses data already in the public domain of the dark web, consistent with legal guidance that obtaining leaked data for legitimate purposes (without unauthorized access) is not unlawful .
- Sensitive Information Content: The leak must contain credentials, personal data, or confidential corporate information of value from a cybersecurity perspective. Examples of qualifying data:
- Credentials: Email addresses, usernames with passwords (hashed or plaintext), authentication tokens, API keys, etc., leaked from breached systems.
- Personal Identifiable Information (PII): Names, contact info, Social Security numbers, financial records, health or insurance data, or other personal data exposed in a breach.
- Corporate/Proprietary Data: Internal documents, client lists, source code, databases or any corporate records leaked online. This might include intellectual property or strategic plans that have been dumped publicly by attackers.
- New and Unique Records: The value to InsecureWeb is in unique records that were not already known. The submission should ideally be a new breach or dataset that InsecureWeb has not yet indexed. Datasets already in our database or previously reported will not be rewarded (or will receive a reduced reward if only a small portion is new). Example: If a contributor submits a user/password dump of a website and 90% of those credentials are already in InsecureWeb’s collection, we may only reward the remaining 10% that are new. (Contributors are encouraged to focus on fresh breaches or expanded data sets, not ones broadly available for a long time.)
- Complete, Verifiable Data: Submissions should include enough data to be actionable. Generally, a dumped database or file with thousands of entries is expected. Small samples (e.g. just one or two credentials) are not sufficient unless they are evidence of a larger breach the contributor can help us access. The data should be in a usable format (text, CSV, SQL dump, etc.) and not deliberately corrupted. InsecureWeb may ask for verification by providing a hash or snippet of the data to confirm it matches the dark web source.
- No Illicit or Non-Public Materials: Do not submit data that is not meant to be public or is protected by law in a way that makes even possession illegal. For instance, do not submit classified government information, proprietary data obtained via insider theft, or content like child exploitation material (which is strictly illegal to possess under any circumstances). The program is about typical data breaches (accounts, personal data, etc.), not other illegal contraband. If such non-qualifying content is intermixed in an otherwise qualifying data dump, the contributor should filter it out and report it to the appropriate authorities instead of submitting to us.
In summary, the ideal submission is a dataset from a recent breach that has been released on the dark web for anyone to download, containing a significant volume of credentials or sensitive records that InsecureWeb can ingest to alert affected parties. The contributor must not have broken any laws to obtain it – it should be as if they stumbled upon the data on a dark web site already leaked by someone else.
Submission Process
To maintain a clear, secure workflow, InsecureWeb has a structured submission and review process. Contributors should follow these steps:
- Enrollment & Verification: Prospective contributors register for the program via InsecureWeb’s portal. This involves creating a contributor profile and undergoing identity verification. For individual researchers, this may require providing government-issued ID and proof of professional background (such as a LinkedIn profile or references). Organizations will register through an authorized representative. Once verified and approved, the contributor is given a unique Contributor ID and access to the secure submission channel.
- Accept Program Agreement: Before any data is submitted, the contributor must read and accept the Reward Program Agreement (covering rules, confidentiality, and legal compliance). This agreement reiterates that the contributor will only submit data obtained ethically and that they consent to InsecureWeb’s use of the data for security purposes. It also includes a non-disclosure clause: contributors should not publicly share or sell the data elsewhere before or after submission, so as not to amplify the exposure.
- Prepare the Data for Submission: The contributor should collect the leaked dataset and prepare any accompanying information. They should document where and when the data was found (e.g. “Discovered on XYZ hacker forum on TOR on May 1, 2025”). If possible, gather a URL or thread reference, and note any context (who leaked it, any associated hacker notes about the breach). The actual data file should be packaged securely (e.g. compressed and encrypted if sending via email/upload). InsecureWeb may provide a PGP public key or a secure upload form in the portal to ensure data in transit is encrypted.
- Submit via Secure Channel: Using the provided portal or a secure email to our dedicated intake address, the contributor submits the breach data. The submission typically includes:
- A brief description of the data (origin, type of information, suspected source of breach, date found).
- The data file itself (or a download link if extremely large, though direct file upload is preferred).
- Any evidence of public availability (such as screenshots of the forum post or pastebin, to help verify legitimacy).
- The contributor’s reference ID and contact info (so we can follow up).
- After submission, InsecureWeb will send a confirmation of receipt. This confirmation will be timestamped and attribute the submission to the contributor (important in case multiple people submit the same leak – we credit the first verifiable submission). The confirmation will also include an ID for the case for tracking.
- InsecureWeb Review & Verification: Our threat intelligence team will analyze the submission. This involves verifying that the data is authentic and leaked (not fabricated), that it indeed contains sensitive information, and that it was publicly posted as described. The team may attempt to visit the provided dark web source to cross-verify that the data was obtainable without special authorization. We will also cross-check the data against our existing breach database to determine how many unique new records it contains. During this phase, we might contact the contributor for clarifications or additional info. For example, if a password in the dump is hashed, we may ask if the contributor found any decryption or if they have only the raw dump. Timely cooperation will speed up review.
- Acceptance or Rejection Decision: Once analysis is complete, InsecureWeb will decide to accept or reject the submission:
- Accepted – if the data meets all criteria (public source, sensitive content, largely new records, legally obtained) and proves useful, we will approve it for reward. The contributor is notified of acceptance, told how many records were counted as unique and eligible, and the corresponding reward tier (see Reward System below). An acceptance email or message will outline the next steps to claim the reward (and if applicable, how the contributor would like to be recognized publicly).
- Rejected – if the data fails to meet requirements, we notify the contributor with the reason. Common reasons for rejection: the dataset was already known/previously submitted, the data is not sensitive enough or is too small, it was found to be acquired through unethical means, or it contained disallowed content. If possible, we provide feedback. Minor issues might be correctable (e.g. if the only issue was format, we might ask for a re-submission in correct format rather than outright reject). If rejected, no reward is given, and the contributor must not use the data in any unlawful way (the agreement prohibits using it maliciously regardless of reward).
- Reward Delivery: For accepted submissions, rewards are calculated and delivered. The Rewards & Tiers section below details how reward amounts are determined. InsecureWeb will typically pay monetary rewards via electronic means (ACH transfer, PayPal, or another agreed method) within a set time frame (e.g. within 30 days of acceptance). If the contributor opts for an alternate reward like service credits or donation, those will be arranged in the same timeframe. The contributor may need to fill out a form (e.g. tax form W-9 for U.S. citizens if the reward is cash above a certain amount, as required by law).
- Recognition (Optional): InsecureWeb respects privacy – contributors can choose to remain anonymous publicly. However, if they desire recognition, we will gladly acknowledge their contribution. We maintain a “Hall of Fame” page (or leaderboard) for the reward program. After a submission is accepted, the contributor can opt-in to have their name/alias listed along with a tier ranking (e.g. “Gold Contributor – Jane Doe from XYZ Corp, for discovery of ABC Breach”). Public recognition is purely optional. Some organizations might prefer a case study or joint press release instead, whereas independent researchers might prefer an alias. We will only publish details with consent.
- Follow-Up and Collaboration: After successful submissions, InsecureWeb may engage with contributors for follow-up. This could include sharing insights about how the data was used (e.g. number of customers notified) or inviting the contributor to share more intel in the future. Contributors who consistently provide valuable data may be invited to special collaboration channels or given premium access to certain InsecureWeb services as a perk (in addition to rewards).
Throughout the process, integrity and security are paramount. Both the contributor and InsecureWeb must handle the leaked data carefully. InsecureWeb will store submitted breach data in a secure environment with proper access controls and encryption, adhering to data protection best practices . Contributors are urged to delete any local copies of sensitive data after submission (to minimize risk) or securely store it if needed, and to not disclose the data to third parties. InsecureWeb’s team may also coordinate with law enforcement or the affected company if the breach is not yet known – the contributor might be asked for cooperation or more details as part of responsible disclosure (though InsecureWeb will take the lead on notifying victims). Importantly, contributors will not be penalized if the affected company takes legal action against the original hackers – since our participants only provided already-public data in good faith, they are protected as per our terms and DOJ guidelines for good-faith security research .
Tiered Reward Structure
InsecureWeb employs a tiered reward system to ensure rewards are commensurate with the volume and value of data contributed. The reward is primarily based on the number of unique records from the submission that are accepted and ingested into our database. Higher-impact contributions (i.e. larger or more sensitive dumps) receive larger rewards. This tiered approach encourages contributors to seek out significant breaches and also provides clarity on what payout to expect. Below is an outline of the reward tiers (all amounts are examples; final values will be defined in the official program policy and may be adjusted over time):
- Tier 1 – Bronze Contributor: Small Leaks – e.g. up to 1 000 000 unique new records accepted. Reward: $100 (baseline) or equivalent value in service credits. This tier covers smaller breaches or datasets (for example, a few thousand customer records from a minor website). It ensures even modest contributions receive some compensation as a gesture of appreciation.
- Tier 2 – Silver Contributor: Medium Leaks – e.g. 5 000 000 unique new records. Reward: approximately $500 (or option for credits or partial cash+credits). This is for medium-sized breaches – The Silver tier acknowledges this with a substantially higher reward than Bronze. Contributors in this tier are also eligible for a one-year InsecureWeb service credit (in addition to or in lieu of cash) if they prefer, which they could use to monitor their own organization or clients.
- Tier 3 – Gold Contributor: Large Breaches – e.g. 10 000 000 unique new records. Reward: approximately $1,000. Breaches of this size (in the six-figure record count) are significant and likely involve a major data exposure. Gold contributors have provided a dump sizeable enough to affect a large population. The reward reflects the importance – it may also be tailored by the exact count.
- Tier 4 – Platinum Contributor: Mega Breaches – e.g. 20 000 000+ records (up to millions). Reward: $2,000 and up, potentially capped for extremely large dumps or handled case-by-case. This tier is for very large data leaks, such as massive database dumps affecting hundreds of thousands or millions of people. In many cases, these are high-profile breaches. While we want to reward such finds, we also must manage budget limits – we might institute a cap (for example, capping at $5,000 for any single breach submission, even if it has millions of records). However, we reserve flexibility: truly exceptional contributions (unique data in the millions or particularly critical data types) might get a bonus above the standard to recognize the value. Platinum contributors also get special recognition – for instance, an offer to be featured (with permission) in an InsecureWeb press release or research blog (highlighting their contribution to protecting the community), and possibly a lifetime subscription credit to our monitoring service for their personal/company use.
- Bonus Multipliers (Special Cases): While the primary metric is record count, quality and sensitivity can also influence rewards. The program may offer bonus rewards for data that is especially critical. For example, if a leak contains a large number of high-value corporate credentials (say credentials that could access critical infrastructure or government systems), or a trove of financial data (credit card numbers, bank account info), InsecureWeb might add a bonus of 20% to the base reward for that tier. Similarly, if the contributor’s find leads to prevention of an imminent threat (like discovery of network access credentials being sold that allow a major attack to be averted), we could award a discretionary bonus or a spot award. These are evaluated on a case-by-case basis by InsecureWeb’s review board.
- Multiple Submissions: Contributors can earn multiple rewards over time for different breaches. Each submission is evaluated independently and rewarded according to the tiers above. If a single contributor in aggregate submits many breaches, we may also have cumulative rewards – e.g., after 5 accepted submissions, a bonus $500 or an upgrade to a higher tier status in the program. This encourages ongoing participation. We also rank contributors by total records contributed in a year; top contributors might receive an annual “Top Contributor” prize or additional honor (like free conference passes or swag packs), in addition to the per-submission rewards.
The reward amounts and structure are set to be competitive with industry standards while avoiding incentivizing any unethical behavior. We benchmarked these rewards in line with similar programs. For instance, major tech companies’ bug bounty programs often have minimum payouts around $500 for valid reports , and scale up with impact. Our tiers ensure a minimum reward (even Bronze provides a baseline payout for small leaks), and then scale such that large contributions yield four-figure rewards. The exact dollar values may be adjusted (and possibly increased) as the program evolves, based on budget and volume of submissions. InsecureWeb is committed to providing fair compensation to researchers, as we recognize the value of crowd-sourced threat intelligence. It’s also worth noting that contributors may choose to receive the reward in different forms – which leads to the next section.
Important note: only new and unique records that can be linked to the organization who had the breach and are verified will count towards this program. Generic combolists with just users and passwords are not accepted as valid.
Reward Types and Incentives
Contributors can receive their reward in a form that best suits them, subject to legal and practical considerations. InsecureWeb offers several types of rewards, commonly used in the cybersecurity community, to make participation attractive:
- Monetary Rewards (Cash): The default for most submissions is a cash payment (via secure electronic transfer). Cash is often the most straightforward and universally appreciated reward. This mirrors typical bug bounty programs, where researchers receive money for their findings. We ensure payments are made in compliance with tax laws (forms as needed) and via reputable payment processors. (For international contributors, currency equivalents can be arranged, but the program operates in USD baseline.) Legality: Paying cash for legitimately obtained leaked data is legal as long as we are not paying the actual thief. We require the contributor’s certification that they are not the data thief, thus avoiding any suggestion that we are rewarding criminal activity. This approach is similar to how Facebook’s “data bounty” program pays rewards (though Facebook opted to donate to charity to avoid even the perception of incentivizing scraping) . In our case, we directly reward the researcher because the program is carefully scoped to only reward ethical actors.
- Service Credits: As an alternative to cash (or in combination), contributors may opt to receive their reward (or a bonus on top of cash) as InsecureWeb service credits or subscriptions. For example, an individual researcher might prefer a year’s free access to InsecureWeb’s Dark Web monitoring platform for their personal or business use. An MSSP (Managed Security Service Provider) who contributes might choose credits that allow them to enroll additional clients in InsecureWeb monitoring. Service credits can be valuable, often at equal or greater face value than the cash (we may offer, say, credits worth 20% more than the cash equivalent, as an incentive). This is a common practice in some reward programs where the company’s product is offered – it builds loyalty and showcases our platform’s capabilities. It’s also legally straightforward, essentially a promotional allowance.
- Public Recognition: Many researchers value acknowledgment for their contributions. InsecureWeb will maintain a public Hall of Fame or Leaderboard (updated quarterly, for instance) listing top contributors (with their consent). Recognition can include:
- Listing the contributor’s name or alias and their achievement (e.g., “Contributor Platinum – contributed 1.2 million leaked records in 2025”).
- Issuing digital badges or certificates that contributors can display (useful for professionals’ resumes/CVs to demonstrate their positive contributions to security).
- Featuring certain contributors in blog posts or case studies. For example, we might write an article about how a particular breach was discovered through this program (with the contributor’s perspective) – shining a spotlight on their work, similar to how some security blogs credit external researchers for discoveries.
- Invitations to speak at webinars or events hosted by InsecureWeb on threat intelligence, giving credit to contributors as subject matter experts.
- Public recognition is a reward in itself (social capital) and is commonly used in bug bounty and threat intel communities. For instance, many bug bounty programs publish a “Thanks” page listing researchers who reported issues, which is a point of pride in the community. We aim to do the same for data leak contributors, helping build their reputation as defenders.
- Swag and Other Perks: In addition to the above primary rewards, InsecureWeb may provide branded swag (T-shirts, stickers, etc.) or other small tokens of appreciation, especially for frequent contributors. While not the main incentive, these help build a community spirit. We might also organize an annual raffle or bonus for active participants (e.g., giving away a conference ticket, a piece of security hardware like a YubiKey, etc.). These rewards are “soft” but foster goodwill.
- Charitable Donations (Optional): If a contributor prefers not to accept a reward personally (for example, an employee of an organization might be barred from accepting cash, or a researcher might simply wish to do good), we offer the option to direct the equivalent reward value to a charity or non-profit of the contributor’s choice. This is inspired by programs like Meta’s data scraping bounty, which channels rewards to charity to avoid any gray areas . In our case, while we don’t require charity (we’re comfortable paying the researcher directly since the scope is ethical), we still want to support this option. It could be a win-win: the researcher gets recognition for donating their reward, and we fulfill the payout in a socially responsible way.
- Access to Threat Intelligence Feeds: As a form of reward, qualified contributors might be given special access to InsecureWeb’s intelligence data. For example, a contributor could receive access to certain premium breach data feeds or APIs for their own security research. This is similar to how some threat intel communities operate (contributors earn access by contributing). A real-world analog is the CRDF Threat Center, which encourages users to report malicious URLs and provides a leaderboard; by hitting certain levels, reporters presumably gain recognition or access . In our case, a contributor might get to use our dataset or tools, which can be highly valuable for their work. This type of reward is less common in traditional bug bounties, but more common in crowdsourced threat intel programs – it builds a partnership feel.
Legality and Common Practice: All the above reward types are legal and widely used in the industry for similar collaboration programs. Cash rewards are standard in bug bounty programs across companies like Google, Microsoft, and many cybersecurity firms (with researchers often paid per report) . Service credits are also commonly offered, especially by smaller firms or those catering to a specific community – they allow the contributor to directly benefit from the product they are helping improve. Public recognition is an established practice and does not run afoul of any laws; it’s a mutually beneficial approach (researchers build reputation, company demonstrates engagement with the community). We ensure any public recognition is with consent to avoid accidentally outing someone who prefers anonymity (especially given the sometimes legally gray nature of dark web research). Finally, offering a charity donation option aligns with best practices when there could be concern about incentivizing data collection – it was explicitly the model Meta used to avoid encouraging scraping activity while still rewarding the finder . We include it to give contributors flexibility and to highlight our program’s positive intent (making the internet safer, not profit from data).
By providing a range of reward options, the program can appeal to a broad set of participants. Some may be driven by financial gain, others by altruism or professional development. InsecureWeb’s goal is to nurture a community of contributors who feel valued and rewarded in whichever way suits them, for their help in identifying leaked data and protecting organizations.
Examples of Similar Programs and Best Practices
In developing this reward program, InsecureWeb has looked at industry best practices from other dark web monitoring and cybersecurity initiatives. While our program is among the first of its kind specifically for leaked data submissions, there are analogous programs worth noting:
- Meta (Facebook) “Data Abuse Bounty” Expansion: In 2021, Meta expanded its bug bounty program to include a data bounty track for scraped or exposed Facebook user data . They offered rewards for reports of open databases or datasets containing Facebook user information that were not previously known to them. Notably, Meta required a minimum of 100,000 unique user records in a dataset for it to qualify , emphasizing significant volume. The “bounty” for such data leaks was paid in the form of a charitable donation (matched by Meta) rather than directly to the researcher, specifically to avoid incentivizing anyone to scrape data themselves . This program’s existence validates the concept of paying security researchers for discovering leaked data. Our program takes a similar stance on requiring unique data and not paying for anything already known, but we allow direct rewards since our scope is clearly limited to publicly leaked data (not encouraging new scraping). Meta’s approach showed that large organizations see the value in crowdsourced discovery of exposed data, and the importance of structuring the reward to stay on the right side of ethics (hence the donation mechanism). We have incorporated the lesson that clarity in rules (like “must be unique and not previously reported”) is crucial to avoid duplicate reports – similarly, InsecureWeb will only reward the first finder of a dataset to incentivize timely reporting.
- Bug Bounty Programs (Google, Microsoft, etc.): Traditional bug bounty programs aren’t about leaked data, but many principles apply. Companies like Google, Microsoft, and countless others run structured programs where ethical hackers are rewarded for vulnerabilities they find. Common practices from these programs that we emulate include: clear eligibility (they often exclude malicious actors and employees), defined submission processes, tiered rewards by severity/impact, and public recognition (many have Halls of Fame). For instance, Google’s Vulnerability Reward Program and others set minimum payouts (often a few hundred dollars) and scale upward for more impactful discoveries . We mirror this with our tiered payouts and minimum reward levels. Another relevant practice is scope definition: bug bounties clearly state what’s in scope (which systems, types of bugs). Analogously, our program clearly defines in-scope data (public leaks with sensitive info) and out-of-scope (data obtained by hacking). By aligning with these well-established frameworks, we ensure our program is familiar and fair to participants. The bug bounty industry has shown that clear rules and fair pay can attract a global community of talent to improve security . We expect a similar enthusiastic response by applying those principles to dark web data collection.
- Crowdsourced Threat Intelligence Communities: There are communities and platforms that rely on crowdsourcing threat intel (though not all pay money). For example, the CRDF Threat Center is a non-commercial project where users submit malicious URLs; CRDF set up a reward and leaderboard system to encourage more submissions, essentially “gamifying” the reporting of phishing and malware sites . This demonstrates that people are willing to contribute to threat intelligence databases when there’s an incentive structure (even if the incentive is points or recognition). Similarly, AlienVault OTX (Open Threat Exchange) is a platform where researchers share threat indicators freely, earning reputation – while it doesn’t provide cash, it shows the power of information sharing. Our program takes this concept and adds monetary rewards to it, given the value of breach data and the effort often required to find and collect it. The community aspect is something we want to foster; like CRDF’s leaderboard of reporters, we will maintain a friendly competition and recognition system to keep contributors engaged. This aligns with best practices of collaborative defense – sharing data to make everyone safer.
- Have I Been Pwned (HIBP) & SpyCloud (data partnerships): HaveIBeenPwned (run by Troy Hunt) is a well-known breach notification service that aggregates leaked data, somewhat similar to what InsecureWeb does. HIBP doesn’t run a paid program, but Troy Hunt often relies on trusted sources to provide breach files. He has a policy of only using data that was obtained without hacking – usually breaches that are already in circulation publicly – which is exactly our stance. Legal experts have noted that obtaining and using leaked passwords for a legitimate security purpose (like HIBP or our service) is generally lawful, as long as you secure the data and use it to help users, not for nefarious ends . We follow the same logic. Meanwhile, companies like SpyCloud have built large breach datasets via their “Data Partnerships” and in-house collection teams. SpyCloud’s model involves acquiring breach data (they even crack passwords to provide plaintext) and then selling protection services. While SpyCloud’s specific partnerships aren’t public, they likely involve compensating sources or providing reciprocal data. In a blog, SpyCloud emphasizes responsible disclosure and following DOJ guidance when handling stolen data – for instance, not violating CFAA and notifying victims without strings attached . Our program’s rules echo these principles (we won’t ask a victim company to pay us for the data; participating in our program means you agree any victims can get notified freely as a public good). The best practice here is ensuring that our reward program doesn’t inadvertently encourage anything unethical. We reward the act of sharing data to help others, which aligns with the security community’s ethos of responsible disclosure and assistance .
- Government Cybercrime Tip Rewards: As a tangential example, the U.S. government (through the State Department’s “Rewards for Justice” program) sometimes offers monetary rewards for information leading to cybercriminal identification or arrest. For instance, multi-million dollar rewards have been offered for tips about ransomware gangs or state-sponsored hackers . While this is different in nature (law enforcement vs. corporate program), it reinforces the idea that valuable cyber intelligence has a price, and offering rewards can bring forth information that wouldn’t otherwise surface. In our context, the “intelligence” is leaked data that helps organizations. We of course keep our rewards proportional and within legal boundaries (we’re not paying for anything related to hacking itself, just data that’s leaked). But the broader best practice gleaned is the importance of verifying the source and credibility of submissions (just as the government vet tips, we vet data authenticity) and having legal disclaimers in place.
In summary, our program is built on the shoulders of prior initiatives: we take the structured payout and recognition model of bug bounties, the crowdsourcing spirit of threat intel communities, and the ethical guardrails of responsible disclosure programs. By studying these, we have crafted a program that we believe will attract contributors while maintaining integrity. The common thread in all these examples is that clarity and legality are paramount – participants need to know what is expected and allowed. We have made those points clear in our rules. Additionally, the examples show that when done right, these programs create a win-win: contributors are rewarded (or recognized), and organizations (or the broader public) become safer through the intelligence gathered. We aim for the same outcome with InsecureWeb’s reward program – a safer digital world through collaborative monitoring of the dark web.
Legal and Ethical Considerations
Because this program deals with leaked, potentially sensitive data and operates in an area overlapping with cybercrime territory, it is critical to address legal and ethical issues explicitly. InsecureWeb is committed to running the program in full compliance with U.S. law and ensuring that no aspect of the program inadvertently encourages illegal behavior. Below are the key legal considerations and the measures in place to address them:
- No Unauthorized Access (CFAA Compliance): Participants must not engage in any hacking or unauthorized system access to obtain data. The U.S. Computer Fraud and Abuse Act (CFAA) prohibits unauthorized access to computers; our program strictly adheres to this. All data should come from sources where it was openly available (even if on the “dark web”). If a dataset is behind a login or paywall, or requires one to actively breach a system to retrieve it, that is out of scope. The DOJ’s guidance on good-faith security research (2022) states that research not involving unlawful access and aimed at improving security is not to be charged under CFAA . We align with this: as long as participants only collect what’s already leaked and don’t break into any system, they are on legal solid ground. Our rules (and the contributor agreement) explicitly forbid actions like attempting to hack into dark web sites or decrypting encrypted data through illicit means. If a contributor oversteps (e.g., uses a leaked credential to log into a company’s system to prove something), that goes beyond the program’s allowance and will result in disqualification and possibly reporting. We want only passive collection of already-public info.
- No Dealing with Criminals / No Stolen Property Exchange: The program will not reward the original thieves or any accomplices. Legally, this is crucial to avoid “trafficking in stolen property” or being seen as incentivizing crimes. We do not buy data from darknet marketplaces or pay ransoms; we only reward independent security folks who find data. If we suspect a submission is coming from the person who hacked the data in the first place (for example, the submitter is the ransomware gang or hacker trying to double-dip by selling to victims and getting a reward from us), we will reject it and may report that person to law enforcement. The contributor vetting (identity verification) helps here – a criminal is unlikely to provide their real identity. Additionally, our intake process might flag certain patterns (e.g., a contributor who only ever submits data from breaches that haven’t been publicly posted – how did they get it if not involved?). We require contributors to certify the data was obtained through publicly available channels. Any hint that data was acquired via private sale or directly from the hackers will raise red flags. InsecureWeb reserves the right to cancel rewards or ban participants if any unethical behavior is discovered. This protects us from legal liability of “rewarding hacking.” In essence, we act in accordance with the principle that obtaining leaked data with a legitimate purpose is lawful, but obtaining it with criminal intent or through collaboration with criminals is not .
- Intellectual Property and Privacy Rights: Leaked datasets might contain intellectual property or personal data. Normally, using someone’s data without permission could violate privacy laws or contracts. However, because this data is already publicly leaked by a third party, our use of it for cybersecurity purposes falls under legitimate interest and often breach notification duties. We operate similar to a cybersecurity firm or journalist that might lawfully collect breach evidence to inform and protect the public. Nonetheless, we ensure compliance with data protection principles: we only use the data to alert affected parties or enrich our protective services, not for exploitation. We secure the data and limit its use to the stated purpose (preventing identity theft, fraud, etc.). Contributors are also expected to handle data carefully. If a contributor is subject to laws like GDPR (e.g., if they reside in the EU), they should know that once they submit data to us, we become responsible for it – they should not themselves use it for anything beyond the act of reporting. In our disclaimers, we state that by submitting, they confirm they have the right to transfer the data to us for these security purposes. InsecureWeb will likely be considered a data controller of the received personal data, and we will abide by relevant privacy laws (we have internal policies for how long breach data is stored, how it’s protected, etc.). Note: In the U.S., there isn’t a single overarching privacy law like GDPR, but laws like California’s CCPA could consider breach data containing personal info as “personal information” we hold. We assert a legitimate business/security need to hold it (monitoring for credential abuse, etc.), and we do not sell it in the sense of marketing – it’s used to protect the same individuals whose data it is. All this will be detailed in our privacy policy and the program terms, so contributors (and their organizations) know that the data will be handled lawfully after submission .
- Responsible Disclosure to Affected Parties: Ethically, when dealing with breach data, there is an expectation to help notify victims. As noted in DOJ guidelines, if you possess stolen data, you should inform the rightful owner that you have it . InsecureWeb’s policy (independent of the reward program) is to conduct responsible disclosure. That means if someone submits a breach of Organization X’s data and X is not aware, we will attempt to confidentially notify Organization X (or the public, if appropriate) so they can mitigate damage. We do this for free – we do not require the organization to be a client or to pay for our services to get their data back (we avoid the unethical practice of withholding knowledge for leverage, which the DOJ explicitly warns against ). Contributors should be aware of this, and by participating they agree that InsecureWeb may share the pertinent leaked data with the affected entity or individuals as part of harm mitigation. We will not disclose the contributor’s identity in these notifications without permission; we typically would say “we obtained information that your data was found on the dark web” and proceed to help, focusing on the data, not the source. This aligns with practices at companies like SpyCloud, which separate such disclosures from sales and focus on being “good internet citizens” . Legally, this helps protect all parties: if we notify victims, we are less likely to run into issues of “withholding evidence” or any insinuation of impropriety. It also provides an additional ethical motivation for contributors – they know their find will be used to alert and protect victims, not just to enrich a database.
- Disclaimers of Liability: The program terms will include standard legal disclaimers. Contributors participate at their own risk. InsecureWeb cannot guarantee that by participating a contributor might not face some third-party claim (for example, if an overzealous breached company tried to accuse a finder of “possession of stolen data”, even if unwarranted). We will, of course, stand by ethical contributors and can explain the legitimacy of our program if needed, but our terms will likely ask participants to acknowledge this risk. We also disclaim any liability if a submission inadvertently causes issues – say a contributor submits data that they didn’t have rights to and there’s a lawsuit, the contributor would bear responsibility for obtaining it wrongfully contrary to our rules. Essentially, contributors must follow the rules and laws; if they break them, we are not liable for their actions. Conversely, if we fail to pay a legitimate reward due to some unforeseen reason, our liability might be limited to the amount of the stated reward, etc. All these are typical clauses to prevent legal disputes. The agreement will also clarify that participation does not make the contributor an employee or contractor of InsecureWeb – they are an independent party providing a voluntary submission, so no labor laws or benefits apply.
- Program Integrity and Changes: We include a note that InsecureWeb reserves the right to modify or terminate the program if required (for instance, if laws change or if we find the program is being abused). We will do so transparently, and any pending rewards would still be honored. We also maintain the right to escalate any suspected criminal submissions to law enforcement. If someone submits something that indicates an ongoing crime (like data that was not public or mentions of future attacks), we might involve authorities for the greater good. This is in the legal consideration to ensure we’re not harboring illicit activity.
- Jurisdiction: The program is based in the U.S. and follows U.S. laws. Participants from other countries are welcome, but they are responsible for ensuring that receiving a reward and contributing data doesn’t violate their local laws. (For example, some countries have strict data handling laws – a researcher should ensure they can send us the data legally. In many cases it’s fine if it’s for security research, but the onus is on them to check.) We may restrict participation from certain regions if required by law (e.g., countries under U.S. sanctions, or if export control regulations somehow apply to sharing certain data). These details will be in the fine print.
In conclusion, the legal and ethical framework of the InsecureWeb Reward Program is designed to prevent misuse and comply with all laws. By requiring publicly leaked data only, verifying identities, forbidding any wrongdoing, and committing to help those affected by the leaks, we create a program that stands on the right side of the law. Participants can feel confident that by working with us, they are aiding cybersecurity efforts in a lawful manner. As one legal reference notes, obtaining leaked data for a legitimate purpose with proper care is acceptable – our entire program is predicated on that legitimate purpose: to reduce harm from data breaches. We also reflect the Justice Department’s guidance for handling stolen data (don’t hack to get it, do inform victims, don’t extort) , which is baked into our rules. All contributors are expected to uphold the highest ethical standards. Any attempt to deviate will be dealt with firmly to protect the integrity of the program and the safety of the community.
By participating in the InsecureWeb Dark Web Data Leak Reward Program, you affirm that you have read and understood this policy document and agree to abide by all the rules, guidelines, and legal requirements herein. Through collaborative vigilance, we can turn the tide against cyber threats on the dark web – rewarding the defenders who bring hidden breaches to light, and thereby helping countless individuals and organizations stay secure. Together, in an ethical and lawful manner, we will shine a light into the dark corners of the web for the greater good.
