As a leading UK financial institution, we recognise the importance of privacy and take security issues very seriously.
We invest significant resources in ensuring our products and services are as safe and secure as possible, but we do recognise there may be occasions where people have a concern they want to raise with us. We greatly appreciate the efforts of security researchers and discoverers who share information on security issues with us, giving us a chance to improve our products and services, and better protect our customers.
We are committed to addressing any reported security issues through a coordinated and constructive approach. A Vulnerability Disclosure is the way any suspected issue can be reported which relates to the confidentiality, integrity, or availability of bank or customer data or systems.
Reporting Security Issues
If you believe you have discovered a vulnerability in any of our products or services, or have a security incident to report, please email our Cyber Security Team at security@virginmoney.com.
The report should be in English and include all details necessary to understand the suspected vulnerability and allow us to reproduce it, including:
- The website, application, or service where the vulnerability has been observed.
- A brief description of the type of vulnerability, for example an "XSS vulnerability".
- A benign, non-destructive, proof of exploitation, wherever possible.
- The identification of limiting factors e.g., non-Admin user, security HTTP headers etc.
Process
After we have been notified of legitimate issues, we'll endeavour to acknowledge your emailed report, assign resources to investigate the issue and fix potential problems as quickly as possible.
Once we have received a vulnerability report, we undertake the following to address the issue:
- We will investigate and verify the vulnerability.
- If appropriate, we will address the vulnerability and release an update/patch to the software. If this cannot be done quickly or at all, we will provide information on recommended mitigations.
- We will update the issue reporter on progress.
We ask that the reporter keeps any information regarding the vulnerability confidential so that we have time to investigate and address any issues.
Bug bounty
Virgin Money UK PLC does not offer a paid bug bounty programme.
Guidance
Security researchers must not:
- Access unnecessary amounts of data. For example, 2 or 3 records is enough to demonstrate most vulnerabilities, such as an enumeration or direct object reference vulnerability.
- Use high-intensity invasive or destructive technical security scanning tools to find vulnerabilities.
- Violate the privacy of staff, contractors, services, or systems. For example, by sharing, redistributing and/or not properly securing data retrieved from our systems or services.
- Communicate any vulnerabilities or associated details using methods not described in this policy, or with anyone other than their assigned security contact.
- Modify data in Virgin Money systems or services which does not belong to the researcher.
- Disrupt Virgin Money services or systems.
- Social engineer, 'phish' or physically attack Virgin staff or infrastructure.
- Disclose any vulnerabilities in Virgin Money systems or services to 3rd parties or the public, prior to Virgin Money confirming that those vulnerabilities have been mitigated or rectified.
Legalities
This policy is designed to be compatible with common good practice among well-intentioned security researchers. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause Virgin Money UK PLC to be in breach of any of its legal obligations, including but not limited to (as updated from time to time):
- The Computer Misuse Act (1990)
- The General Data Protection Regulation 2016/679 (GDPR) and the Data Protection Act 2018
- The Copyright, Designs and Patents Act (1988)
Virgin Money UK PLC will not seek prosecution of any security researcher who reports any security vulnerability on a Virgin Money UK PLC website, application, or service where the researcher has acted in good faith and in accordance with this disclosure policy.