Meta

Meta
FacebookInstagramXYouTube
Meta Bug Bounty
Meta Bug Bounty overviewLeaderboardsProgram scopeProgram termsHacker Plus benefitsHacker Plus terms

Program tools
SSRF validatorTest accountsFBDLAccess token debuggerGraph API explorer

Payout guidelines
Payout guidelines overviewMobile remote code executionAccount take-overMeta hardware devicesServer side request forgery (SSRF)Platform privacy assertions2FA bypassContact point deanonymizationPage admin disclosureCross-site leaks

Data Abuse program
Data Abuse program overviewData Abuse termsReport abuseManage reports

Site terms and policies
Privacy policyTermsCookie policy

Meta Bug Bounty
Meta Bug Bounty overview
Leaderboards
Program scope
Program terms
Hacker Plus benefits
Hacker Plus terms
Program tools
SSRF validator
Test accounts
FBDL
Access token debugger
Graph API explorer
Payout guidelines
Payout guidelines overview
Mobile remote code execution
Account take-over
Meta hardware devices
Server side request forgery (SSRF)
Platform privacy assertions
2FA bypass
Contact point deanonymization
Page admin disclosure
Cross-site leaks
Data Abuse program
Data Abuse program overview
Data Abuse terms
Report abuse
Manage reports
Site terms and policies
Privacy policy
Terms
Cookie policy
Meta Bug Bounty
Meta Bug Bounty overview
Leaderboards
Program scope
Program terms
Hacker Plus benefits
Hacker Plus terms
Program tools
SSRF validator
Test accounts
FBDL
Access token debugger
Graph API explorer
Data Abuse program
Data Abuse program overview
Data Abuse terms
Report abuse
Manage reports
Payout guidelines
Payout guidelines overview
Mobile remote code execution
Account take-over
Meta hardware devices
Server side request forgery (SSRF)
Platform privacy assertions
2FA bypass
Contact point deanonymization
Page admin disclosure
Cross-site leaks
Site terms and policies
Privacy policy
Terms
Cookie policy
Meta Bug Bounty
Meta Bug Bounty overview
Leaderboards
Program scope
Program terms
Hacker Plus benefits
Hacker Plus terms
Program tools
SSRF validator
Test accounts
FBDL
Access token debugger
Graph API explorer
Payout guidelines
Payout guidelines overview
Mobile remote code execution
Account take-over
Meta hardware devices
Server side request forgery (SSRF)
Platform privacy assertions
2FA bypass
Contact point deanonymization
Page admin disclosure
Cross-site leaks
Data Abuse program
Data Abuse program overview
Data Abuse terms
Report abuse
Manage reports
Site terms and policies
Privacy policy
Terms
Cookie policy
Legal
* All payout amounts are in USD

©2025 Meta.

OverviewTerms and Conditions

DATA ABUSE BOUNTY PROGRAM

Terms and conditions

If you know of any third-party app currently or formerly operating on Facebook or Instagram that has violated policies or terms governing these platforms (including Developer Policies and Meta Platform Terms), please alert us right away. We are not asking you to undertake an investigation or gather new or additional information on your own—this program only applies to situations in which you already have specific and direct knowledge of abuse of user data.

Throughout these terms and conditions

  • “Abusing” user data refers to buying, selling, disclosing, transferring, or using Facebook or Instagram user data, to include credentials, in any manner prohibited by policies or terms governing the Facebook or Instagram platforms or any applicable laws

Before reporting, please review this page, including the General Terms, Requirements for Data Abuse Bounty reports, and Data Abuse Bounty program reward eligibility. If you are looking to report another type of issue or for other information about Facebook, please use the links below for assistance:

  • If you believe you have found a security vulnerability on Facebook
  • If your account or a friend’s account is sending out suspicious links
  • To report abusive conduct you see on Facebook
  • For any other questions or concerns, please visit our Help Center
  • For program updates and news about our Data Abuse Bounty program, please follow our Facebook page

General terms

We aim to reward those who report a third-party app currently or formerly operating on Facebook or Instagram that has abused user data. Monetary rewards may be made to those whose reports lead to discovery of significant actionable abuse. Whether a specific report merits a reward is entirely at our discretion, based on impact, quality of the report, and other factors. To be eligible for a reward, you must not violate any applicable laws or regulations, including laws and regulations prohibiting unauthorized access to user data. You also must not violate any of Meta Terms and Policies or the terms and policies of any member of the Meta family of companies.

To participate in the program, you must:

  • Adhere to the Requirements for Data Abuse Bounty reports (see below).
  • Meet the eligibility requirements described in Data Abuse Bounty program reward eligibility (see below).
  • Submit your report via our report form and respond to follow up requests from Meta. Please do not contact Meta employees directly or through other channels about a report unless a Meta employee reaches out to you first.

In turn, we will follow these guidelines when evaluating reports under our program:

  • We determine reward amounts based on a variety of factors, including the impact and quality of the report. While there is no maximum, high-impact reports have garnered as much as $40,000* for people who bring them to our attention. If we pay a reward, payment will be made after we conclude our investigation into the issue you report.
  • We seek to pay similar amounts for similar issues, but reward amounts and qualifying reports may change with time. Past rewards do not necessarily guarantee similar rewards in the future.
  • In the event of duplicate reports, we provide a reward to the first person to submit a report that leads to discovery of significant actionable abuse. Meta determines which report qualifies for an award.
  • You may donate a reward to a recognized charity (subject to Meta approval), and we will double reward amounts that are donated in this way.
  • We reserve the right to publish the results of our investigation.
  • All rewards must be permissible under applicable laws, including US trade sanctions and economic restrictions.

Note that your use of Meta services and the services of any member of the Meta family of companies, including for purposes of this program, is subject to Meta Terms and Policies (https://www.facebook.com/policies) and the terms and policies of any member of the Meta family of companies (https://www.facebook.com/help/111814505650678) whose services you use. We (and any member of the Meta family of companies whose services you use) may retain any communications about issues you report for as long as we deem necessary for program purposes, and we may cancel or modify this program at any time.

Requirements for data abuse prevention reports

Your report must describe:

  • The operator of the applicable third-party app, including the name of the app and if known, the relevant appID;
  • The actions taken by the app or website that violate policies or terms governing the Facebook or Instagram platforms or are otherwise unlawful;
  • The nature and scope of the Facebook or Instagram user data abused;
  • Proof of the abuse being reported; and
  • Any information you have about the reason or purpose for the third-party app operator’s conduct.

Your report should include all instances of abusive conduct you are aware of that relate to a single third-party app. Do not submit multiple reports related to the same abusive conduct.

We require that:

  • You do not submit any of the misused user data or credentials to Meta with your report, or at any other time unless Meta specifically requests such information, at which point you should carefully follow any instructions Meta provides about what data to submit and how to submit it.
  • You give Meta reasonable time to investigate an issue you report before making public any information about the report or sharing such information with others.
  • You have specific and direct knowledge regarding the abuse that you are reporting.
  • You do not knowingly submit false information through the Data Abuse Bounty program. Meta will take all necessary actions in response to false submissions, including, but not limited to, banning you from Facebook.

If legal action is initiated by a third party against you and you have complied with our policies, we will take steps, as appropriate, to make it known that your actions were conducted in compliance with our policies.

Nothing in these Terms and Conditions should be construed to prevent you from sharing any information about Meta abuse of user data or credentials with law enforcement. Meta likewise reserves the right to share the information you provide with law enforcement as appropriate.

Data Abuse Bounty program reward eligibility

To be eligible for a Data Abuse Bounty program reward, you must not:

  • Be a resident of, or make your submission from, a country against which the United States has issued export sanctions or other trade restrictions (e.g., Cuba, Iran, North Korea, Sudan, Crimea Region of Ukraine, and Syria);
  • Be employed by Meta, Inc. or its subsidiaries or affiliates;
  • Be an immediate family member of a person employed by Meta, Inc. or its subsidiaries or affiliates; or
  • Be less than 14 years of age. If you are at least 14 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating in the program.

Scope

To be eligible for a reward, the situation must involve:

  • More than 10,000 Facebook and/or Instagram users.
  • Definitive abuse of user data—not just collection
  • A case we were not already aware of or actively investigating.

Explicitly out of scope scenarios:

  • Scraping. Note that in cases of datasets where there is evidence of active misuse and there are over 100,000 unique Facebook user records with PII (e.g. email, phone number, physical address, religious or political affiliation), you can report those at bugbounty@meta.com. Eligible findings will only be rewarded in the form of charity donations.
  • Malware or mass-scale tricking of users to install apps.
  • Non-Facebook or Non-Instagram cases (ex: WhatsApp).

Check back often as we hope to continue to expand the scope of this program. To best understand the intent of the program see the FAQ page.

(Last updated June 18, 2024)
Skip to main content
Meta
Meta Bug Bounty
Tools
Leaderboard
Learn
Submit a report