Microsoft's $20 Million Bounty Record Is Not a Like-for-Like Security Scorecard
Microsoft paid more than $20 million to 562 security researchers in the year ended June 30, a company record. But the total also reflects a broader eligibility policy, a live hacking event and a higher volume of AI-assisted research, leaving the program's operational performance unmeasured.
- Microsoft says it awarded more than $20 million to 562 researchers in the year ended June 30, its largest annual bounty payout and participant count.
- At least $3.1 million of the total came from a live hacking event and newly eligible reports, so the record is not directly comparable with a narrower program.
- The company links a second-half rise in submissions partly to AI-assisted research, but it has not supplied a breakdown of AI-assisted reports or their outcomes.
Microsoft says its bug-bounty program paid more than $20 million to 562 security researchers between July 1, 2025, and June 30, 2026—the largest annual payout and researcher count in the program’s history. Microsoft’s year-in-review announcement describes the results as part of its coordinated-disclosure program, through which researchers report flaws in the company’s cloud, AI, enterprise and consumer products and services.
The headline number is a real record. It is not, by itself, a measure of whether Microsoft is finding more severe flaws, resolving reports faster or improving the disclosure experience. The year also included a broader eligibility rule, a dedicated hacking event and, Microsoft says, a rise in AI-assisted research.

Microsoft’s company-reported 2025–26 bounty-program summary. Source: Microsoft Security Response Center.
The total grew with the program's intake
Microsoft said researchers from 64 countries participated. It received 2,531 eligible reports across 15 bounty programs and made a largest individual award of $200,000, according to an independent account of the program figures.
For context, Microsoft said its previous record was $17 million paid to 344 researchers from 59 countries. The newer total therefore coincides with a materially larger researcher base; it does not establish how the rewards were distributed across reports or people.
In December 2025, Microsoft expanded its approach to what it calls “In Scope By Default.” Critical vulnerabilities could qualify when they had a direct and demonstrable impact on Microsoft online services, including flaws in third-party or open-source code. Microsoft says the change brought more than 300 additional reports and more than $800,000 in awards for work that previously would not have qualified. The policy was introduced roughly halfway through the bounty year, as .
