generated: '2026-07-25' method: searched probe: true summary: >- Insurance Australia Group operates a HackerOne vulnerability disclosure programme at https://hackerone.com/iag. Ownership was confirmed directly against HackerOne's own public GraphQL endpoint, which resolves the team handle "iag" to name "Insurance Australia Group" with website http://iag.com.au — this disambiguates it from International Airlines Group and from AIG (hackerone.com/aig), both of which run separate programmes. It is a disclosure policy rather than a paid bounty: the group's own security.txt, published until mid-2025, stated "No paid bounties currently offered". policy: - https://hackerone.com/iag contact: - mailto:cybersecurity@iag.com.au program: platform: HackerOne handle: iag url: https://hackerone.com/iag owner: Insurance Australia Group owner_website: http://iag.com.au type: vulnerability-disclosure-policy paid_bounties: false bounty_evidence: >- "Policy: No paid bounties currently offered" — group security.txt, last published revision 2025-04-01. evidence: - source: https://hackerone.com/graphql kind: platform-api query: 'query { team(handle: "iag") { handle name website } }' result: '{"handle":"iag","name":"Insurance Australia Group","website":"http://iag.com.au"}' note: Authoritative first-party confirmation of programme ownership. - source: https://hackerone.com/iag kind: disclosure-page title: Insurance Australia Group | Vulnerability Disclosure Policy note: >- Page is a client-rendered SPA, so the policy body is not retrievable anonymously; the title and the GraphQL record are the recorded evidence. - source: well-known/iag-security.txt kind: security.txt note: >- RFC 9116 document served on iag.com.au and six brand domains until mid-2025. Carries Contact, Preferred-Languages, Canonical, Policy and Hiring fields. Withdrawn — see well-known/iag-well-known.yml for the timeline. gaps: - No live /.well-known/security.txt on any IAG host as of 2026-07-25. - No responsible-disclosure page on the corporate website; the Akamai edge returns 403 to non-browser clients for every path below the document root. - security.iag.com.au exists but returns HTTP 401 behind an IBM Verify Identity Access for Web basic-auth realm — an internal surface, not a disclosure page.