Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
Summary
Microsoft's bug bounty program paid out $20 million to 500 researchers between July 1, 2025, and June 30, 2026. The largest single reward given during this period was $200,000.
IFF Assessment
FRIEND
This article highlights Microsoft's investment in incentivizing security researchers, which helps identify and fix vulnerabilities, ultimately strengthening defenses.
Defender Context
Bug bounty programs are a critical part of a proactive security strategy, encouraging external researchers to find and report vulnerabilities before malicious actors can exploit them. Defenders should monitor trends in bug bounty payouts and focus areas to understand emerging threats and common weaknesses.