Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Abercrombie & Fitch Bug Bounty
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Abercrombie & Fitch Bug Bounty? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical $2,250 avg 14 reports indicative
High $2,600 avg 10 reports indicative
Medium $750 avg 23 reports indicative
Low $250 avg 16 reports indicative

$111,950 paid to researchers in total, $22,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
1,458
in 90 days
Resolved
63
all time, last one 4 days ago
Participants
76
hunters engaged
Response efficiency
85%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 1,093–1,458
25 Aug 1,458 reports 22 Sep

Response targets it sets itself

First response
1 day
Triage
2 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 33 days (19 snapshots): intake up 429 reports; response efficiency up 1 points; 90-day payout up $8,750.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

66 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 damian89 402 8 / 10 80%
2 d0xing 250 4 / 7 57%
3 zhero_ 166 9 / 14 64%
4 godiego 109 6 / 11 55%
5 kaiksi 103 4 / 5 80%
6 m0chan 93 4 / 12 33%
7 thaivu 91 3 / 7 43%
8 exploitmsf 79 2 / 3 67%
9 geekysherlock 59 1 / 2 50%
9 val_brux 59 2 / 7 29%
11 curiositysec 57 2 / 3 67%
11 holybugx 57 1 / 2 50%
11 n4vt3j 57 0 / 0
11 proabiral 57 1 / 1 100%
11 securityreapers 57 1 / 1 100%
16 jaleel_khan_98 44 2 / 3 67%
16 jayesh25 44 2 / 2 100%
16 zy9ard3 44 2 / 2 100%
19 mahmoud0x00 39 1 / 4 25%
20 0x7ain_h1 37 1 / 3 33%
21 thefool45 36 1 / 1 100%
22 khaled_hammad 30 0 / 2 0%
23 lytetechnologies 25 0 / 1 0%
24 serdar_uzunay 24 1 / 2 50%
24 solver1 24 1 / 1 100%

Showing the top 25 of 66 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

Abercrombie & Fitch is an American lifestyle retailer that focuses on casual wear.

Responsiveness
85% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Jul 2026
Scope entries
10 HackerOne’s count

Scope

10 assets
AssetTypeEligibilityMax severity
339041767 APPLE STORE APP ID ✓ bounty Critical
383915209 APPLE STORE APP ID ✓ bounty Critical
abercrombie.com URL ✓ bounty Critical
anfcorp.com URL ✓ bounty Critical
com.abercrombie.abercrombie GOOGLE PLAY APP ID ✓ bounty Critical
Show all 10 assets
AssetTypeEligibilityMax severity
com.abercrombie.hollister GOOGLE PLAY APP ID ✓ bounty Critical
corporate.abercrombie.com URL ✓ bounty Critical
hollisterco.com URL ✓ bounty Critical
applications.abercrombie.com/ URL out None
http://nonmerchvendorprofile.anfcorp.com URL out None