Scam Alert: emerson.com — Emerson.com Fixed My Vulnerability Report in 24 Hours — But the Reward Never Arrived
Company / Program: emerson.com
Platform: Self-Hosted · Severity: critical · Scam type: no-payout
Published:
Reported by: Anonymous
I discovered a serious vulnerability on Emerson.com by chance. The website was running on IBM WebSphere, the same platform I was already testing as part of a legitimate bug bounty program hosted on YesWeHack.
I initially contacted Emerson by email and briefly explained the nature of the vulnerability, without revealing its exact location or identifying the affected section of the website.
My request was quickly handled by Benjamin Thal:
https://www.linkedin.com/in/benjamin-l-thal/
I gave him a brief overview of what I had discovered and asked whether Emerson operated a bug bounty or vulnerability reward program. He told me that they did have such a program in place, but that they first needed to receive, review, and assess the full report.
Based on that assurance, I trusted him and submitted a complete, professionally written report. It included screenshots, HTTP requests, detailed reproduction steps, and evidence showing how a vulnerable `OrderId` parameter allowed me to retrieve complete order information.
Emerson fixed the vulnerability in less than 24 hours.
However, when I later asked for an update regarding the reward, what followed was an extremely long and frustrating series of delays and changing explanations. I was repeatedly told things such as:
“Our finance department is on vacation.”
“I have followed up on your payment request.”
“You should receive the payment soon.”
“We need a copy of your passport.”
“The name on your passport does not match the name used in the email correspondence.”
Each time one issue appeared to be resolved, a new reason was given for delaying or withholding the payment. After numerous excuses and contradictory explanations, I came to believe that I had not been treated honestly or fairly.
I eventually stopped pursuing the matter in order to protect my mental well-being, as I found the prolonged exchanges exhausting and increasingly manipulative.
This statement reflects my personal experience and my understanding of the communications I received throughout the disclosure process.