generated: '2026-07-25' method: searched probe: true published: false summary: >- Liberty Global publishes no vulnerability disclosure policy. No security.txt, no responsible-disclosure page, no security contact address, no bug bounty programme it operates. The only artifact that exists is an unclaimed third-party directory entry on HackerOne, recorded below because it is easily mistaken for a programme. No `Security` pointer is wired into apis.yml — there is no policy URL to point at. policy: [] contact: [] security_txt: published: false note: >- /.well-known/security.txt and /security.txt both return 404 on www.libertyglobal.com, the only first-party host that resolves. See well-known/liberty-global-well-known.yml. external_listing: platform: HackerOne url: https://hackerone.com/libertyglobal program_id: 5947 program_name: Liberty Global Ventures is_external_program: true claimed: false offers_rewards: false policy: null policy_url: null disclosure_email: '' disclosure_url: '' scopes: [libertyglobal.com, liberty.com] fetched: '2026-07-25' http_status: 200 assessment: >- This is a HackerOne *external* directory record, not a Liberty Global programme. HackerOne's own JSON marks it is_external_program: true and claimed: false, with a null policy, an empty disclosure email and an empty disclosure URL. Nobody at Liberty Global has claimed it and there is no published brief a researcher could follow. It is a listing, not a front door — and it is named after Liberty Global Ventures, the investment arm, not the operating group. Recorded as evidence, not counted as a disclosure programme. probed: - {url: 'https://www.libertyglobal.com/.well-known/security.txt', status: 404} - {url: 'https://www.libertyglobal.com/security.txt', status: 404} - {url: 'https://www.libertyglobal.com/security/', status: 404} - {url: 'https://www.libertyglobal.com/responsible-disclosure/', status: 404} - {url: 'https://www.libertyglobal.com/vulnerability-disclosure/', status: 404} - {url: 'https://www.libertyglobal.com/report-a-vulnerability/', status: 404} - {url: 'https://www.libertyglobal.com/about/corporate-governance/responsible-disclosure/', status: 404} - {url: 'https://bugcrowd.com/libertyglobal', status: 404} - {url: 'https://security.libertyglobal.com', status: DNS NXDOMAIN} - {url: 'https://trust.libertyglobal.com', status: DNS NXDOMAIN} adjacent_evidence: - source: https://www.libertyglobal.com/about/corporate-governance/data-privacy-protection/ kind: corporate-security-governance-page fetched: '2026-07-25' http_status: 200 detail: >- Names GDPR, the Sarbanes-Oxley Act, ISO 27001, CAS(T) and PCI DSS, and describes a "Digital Confidence" team overseeing privacy, lawful intercept and security. It does not reference a vulnerability disclosure process or publish a security contact. Captured in conformance/liberty-global-conformance.yml. - source: https://www.libertyglobal.com/careers/vacancy/business-information-security-officer-req_00037975/ kind: job-posting fetched: '2026-07-25' detail: >- A live Business Information Security Officer vacancy, and a cybersecurity graduate scheme, confirm a real internal security function exists. It has no public reporting channel. note_for_researchers: >- A researcher who finds a flaw in a Liberty Global property has no documented route to report it to the parent. The practical channels are the operating companies' own programmes (Virgin Media O2, VodafoneZiggo, Telenet) or the developers@libertyglobal.com address advertised on the LibertyGlobal GitHub organisation profile — which sits alongside a blog URL, https://developer.libertyglobal.com, that is NXDOMAIN, so its liveness is unverified.