Bring cybercriminals to justice
CyberCrime Bounty Program In partnership with FortinetWe target the human perpetrators behind cybercrime, not software vulnerabilities or security flaws. We are seeking information about the specific targets named in our active Operation Silent Vector bounties.
Before you go further
This is not a bug bounty program and not a general cybercrime reporting service. It is not for software vulnerabilities, scams, fraud, phishing, identity theft or cyber incidents. It is specifically for information about the cybercriminal targets featured in active Operation Silent Vector bounties.
If you are a victim of cybercrime or fraud, report it to your local law enforcement agency or national cybercrime reporting service.
Active bounties
Individual bounties are published for specific cybercriminal actors, aliases and groups under active investigation. Read the target information pack first, then submit what you know.
Operation Silent Vector I
The first target under the program. The information pack sets out who we are looking for and exactly what information will help.
How it works
Bounty posted
A government, law enforcement agency or private entity posts a bounty for a verified case, reviewed and approved by the Review Board.
Tip submitted
Anonymous tips come in through the secure platform, from the public and from industry insiders.
Intel verified
Submissions are verified, enriched and correlated by the program's intelligence team, with threat analysis support from Fortinet's FortiGuard Labs.
Bounty issued
Validated leads that produce a qualifying outcome, such as an arrest or material disruption, trigger payment.
Why this program exists
What is Cybercrime?
Any criminal activity carried out using computers, networks or digital devices. Ransomware crippling hospitals, business email compromise redirecting millions in payments, large-scale fraud operations, and stolen data sold on darknet marketplaces.
Scale of the Problem
Global cybercrime costs are projected to reach USD 10.5 trillion a year, which would make it the third-largest economy in the world. The FBI took more than 880,000 complaints in 2023 alone. Fewer than one per cent of cybercrimes end in a prosecution.
Current approaches are not enough
Cybercriminals cross borders at speed while law enforcement is bound by jurisdictions, treaties and resources. Firewalls and threat detection protect networks, but they do not hold the people behind the attacks accountable, and bug bounties address product security rather than criminal accountability.
A new approach is needed
Actionable intelligence about cybercriminals already exists, inside criminal communities, among industry insiders, in the research community and among the public. What has been missing is a secure, incentivised, legally structured way to collect it, verify it and get it to agencies that can act.
Our CyberCrime Bounty Program
A first-of-its-kind global program run with Fortinet, extending the Crime Stoppers anonymous reporting model into the cyber domain, with financial rewards for information that leads to arrests or material law enforcement outcomes.
NOT a scam reporting service
We are not set up to receive reports from victims of scams or fraud. Those go to your local scam reporting centre, consumer protection agency or law enforcement. We want intelligence about the people orchestrating attacks, not the attacks themselves, and specifically about the targets named in an active bounty.
Frequently asked questions
About the CyberCrime Bounty Program
Bug bounties reward the discovery of software vulnerabilities. This program targets the human perpetrators behind cybercrime operations: ransomware gangs, business email compromise networks, scam centres and cyber-enabled criminal organisations. The objective is to support investigations, arrests and coordinated international action against those actors.
Who operates the program?Crime Stoppers International administers it, drawing on a network of programs in more than 30 countries and 50 years of anonymous tip infrastructure. Fortinet provides cyber threat expertise, intelligence enrichment and technical support through FortiGuard Labs. The program aligns with the World Economic Forum's Partnership Against Cybercrime framework.
Who can post a bounty?Governments, law enforcement agencies and private entities, for verified cybercrime cases. Each request needs supporting evidence and legal approval, and is reviewed by a multi-stakeholder Review Board before publication.
How it works
Four stages, set out in full above: a bounty is posted and approved by the Review Board, tips are submitted through the secure platform, the intelligence is verified and enriched with Fortinet's analysis support, and a validated lead that produces a qualifying outcome triggers payment.
What happens to my tip after I submit it?It arrives through the secure, encrypted platform and is triaged by the intelligence team, then verified and enriched through multi-source correlation and threat analysis, including support from Fortinet's FortiGuard Labs. Where it meets the threshold for action it goes to law enforcement partners such as INTERPOL and national agencies, through CSI's established information-sharing protocols.
What role does Fortinet play?Fortinet supplies threat intelligence capability through FortiGuard Labs: cyber threat expertise, intelligence enrichment, automated analysis and technical support for bounty verification. It also brings experience from multi-sector coordination including the World Economic Forum's Cybercrime Atlas.
Eligibility
Anyone aged 18 or over who can satisfy the identity verification requirements. That includes citizens, cybersecurity professionals, ethical hackers and industry insiders worldwide.
Who is excluded?- Employees, officers, directors and contractors of CSI, Fortinet, sponsoring partners or any program partner, and their immediate families.
- Anyone subject to current law enforcement investigation, sanctions or government watchlists.
- Anyone who obtained the information by participating in, facilitating or conspiring to commit the cybercrime being reported.
- Anyone located in a jurisdiction under comprehensive international sanctions.
- Law enforcement officers, government officials and intelligence community members who obtained the information in their official capacity.
- Anyone under 18.
Yes, and anonymous submissions are valued for intelligence purposes. To be eligible for a bounty, though, you must complete identity verification, which reflects the jurisdictional and commercial requirements of the payment method.
Tips (submissions)
- Intelligence on criminal forums, darknet marketplaces or threat-actor groups.
- Human-sourced information about individuals suspected of cybercriminal activity.
- Detail on cyber-enabled criminal networks: ransomware operations, BEC schemes, scam centres, trafficking-linked cyber operations.
- Technical indicators of compromise linked to identified threat actors.
- Financial intelligence on cybercrime proceeds, laundering or crypto-based criminal infrastructure.
- Requests for personal cybersecurity help or incident response.
- Product vulnerabilities or software bugs, which go to the vendor's own bug bounty program.
- Scam reports and consumer fraud complaints, which go to national consumer protection agencies.
- Information obtained through illegal hacking or unauthorised access.
- False, misleading, fabricated or malicious submissions.
Only through the secure submission platform. Tips sent by email, social media, telephone or in person will not be considered for a bounty.
What if several people send the same information?The bounty goes to the first tipster whose information is verified as qualifying. Where several people independently contribute different pieces that together lead to an outcome, the Review Board may divide the bounty as it sees fit.
Bounty & Payment
Amounts vary by case and are specified in each bounty listing. The tipster receives 80 per cent of the approved amount. CSI retains 20 per cent as a program administration fee covering platform operation, intelligence triage, compliance and law enforcement coordination.
What has to happen before payment?- The Review Board determines the information is qualifying information.
- It leads to or materially contributes to an arrest, a search warrant, a digital takedown or another qualifying law enforcement, judicial or administrative outcome.
- Jurisdictional and payment processor requirements are satisfied.
- The Review Board approves payment.
- The sponsoring partner confirms funds are available.
Payment depends on law enforcement outcomes, which can take months or years. CSI has no control over the pace of investigations or court proceedings, and nothing can be processed until a qualifying outcome is confirmed and due diligence is complete.
How is payment made, and is it guaranteed?By electronic transfer to a verified bank account in the tipster's name, in United States dollars, with foreign exchange and banking costs borne by the recipient. Payment is not guaranteed. Submitting a tip creates no entitlement, the decision rests solely with the Review Board and is final, and any bounty may be modified, suspended or cancelled.
Am I responsible for tax?Yes, entirely, in your jurisdiction of residence. CSI provides documentation for tax reporting but does not give tax advice. Seek independent professional advice.
Privacy & Security
Yes. It runs on CSI's anonymous reporting infrastructure, developed over almost 50 years, and all submissions travel through encrypted channels built to protect the submitter's anonymity.
Will my identity be shared with law enforcement?No. Identity information provided for payment purposes is strictly confidential and is not disclosed to law enforcement, the sponsoring partner or any third party, except where required by law, court order or regulatory obligation.
How is my personal data handled?In accordance with applicable privacy and data protection law, including the EU GDPR and the Australian Privacy Act 1988. Data is stored securely and kept only as long as necessary or as required by law. Full detail is in the privacy policy.
Legal & Compliance including T&Cs
Every bounty is reviewed and approved by a multi-stakeholder Review Board before publication, and is limited to credible criminal or private investigations with verifiable evidence. Coordination is maintained with national and international law enforcement, and distribution follows an auditable process.
What law governs the terms?The laws of the US state of New Mexico, where CSI, Inc. is registered. Disputes go to good faith negotiation and, if unresolved within 30 days, to binding arbitration under New Mexico processes.
Do I have to keep my participation confidential?Yes. Tipsters must not publicly disclose their participation, the nature of their tip or any detail of payment without written authorisation from CSI. Breaching this can forfeit the bounty.
What happens to what I submit?You grant CSI and its partners a perpetual, irrevocable, worldwide, royalty-free licence to use, reproduce, adapt and distribute it for intelligence analysis, law enforcement coordination and the program's objectives. It becomes part of CSI's intelligence holdings and may be shared with law enforcement partners through established protocols.
Where are the full terms?Read the CyberCrime Bounty Program Terms and Conditions in full. All tipsters must read, understand and agree to them before submitting. For enquiries, send us an email.