White Hat Hackers and Unpaid Bounties: What Are Your Legal Rights?

Legal options for security researchers and companies in bug-bounty and disclosure disputes: authorization, CFAA risk, contract terms.

Ethical hacker working on cybersecurity vulnerability research

How We Help White Hat Hackers Get Paid What They’re Owed

You found the vulnerability, wrote it up carefully, and disclosed it in good faith. Then the company stopped answering your emails -- or worse, started treating you like the problem. Ethical hackers, also known as “white hats,” safeguard critical systems by identifying and reporting security vulnerabilities, and many companies promise financial rewards through “bug bounty” programs for responsible disclosure. Unfortunately, not every hacker gets paid.

At Simon Law Group LLC, we help ethical hackers assert their rights and secure compensation--whether a company failed to honor a bug bounty agreement or never had one in the first place.

The Challenge: No Contract, No Pay?

Many bug bounty programs are informal or vaguely worded, offering rewards “at the discretion” of the company. And in some cases, a company may not have a program at all--but a hacker still responsibly discloses a serious vulnerability. Despite acting in good faith, the hacker is met with indifference or hostility. This is one of the hardest--and most frustrating--situations our clients face.

That’s where we step in.

We often represent ethical hackers who come to us before they disclose a vulnerability, seeking help to negotiate fair terms upfront or structure a legal agreement that ensures compensation upon disclosure. These pre-disclosure negotiations can be sensitive and high-stakes, especially when the target company has no formal bug bounty program in place.

How We Help Ethical Hackers Get Paid

Our legal strategies include:

  • Negotiating pre-disclosure agreements to secure payment terms and limit liability before sharing the vulnerability
  • Asserting contractual and quasi-contractual claims when companies benefit from the vulnerability disclosure but refuse to compensate
  • Navigating jurisdictional complexity, particularly when hackers and companies are based in different countries
  • Advising on safe communication and legal exposure, especially under laws like the Computer Fraud and Abuse Act (CFAA)

White Hat, Black Letter Law

Companies depend on ethical hackers to secure their digital infrastructure--but on payment, many hide behind legal technicalities. We help remind them that ethical hacking, especially when done under a good-faith disclosure, is skilled labor that adds value. And value deserves fair compensation.

A Win for the Cybersecurity Community

Reviewed by

Britt J. Simon, Esq.

Managing Partner

Simon Law Group, LLC

Reviewed May 25, 2026

Call us today

(800) 709-1131

No-cost consultation request
Available Mon-Fri, 8:30 AM-5:00 PM

Our offices

Somerville accepts office visits. Morristown and Flemington are by appointment.

The Brief

Get future legal updates by email.

Subscribe for practical New Jersey legal updates and new firm resources. Do not send confidential facts through this form.

Choose your updates
This is a quick security check to keep automated spam off the form.

Unsubscribe anytime. We don’t share your email, and we don’t fill your inbox.

Related practice areas

Related articles

Consult

Which digital asset, system, contract, or incident is in dispute?

Preserve the agreement, access logs, messages, transaction record, and the date the problem was discovered.

Consultation request. There is no charge to send this form or to talk through your situation.

Address

Use your mailing address. It helps us understand the county, urgency, and follow-up logistics.

If your issue is tied to a court date, deadline, or safety concern, include that timing in the first sentence.

This is a quick security check to keep automated spam off the form.

Contacting us does not make Simon Law Group your lawyer. Representation begins only after you and the firm sign a written engagement agreement.