Responsible Disclosure Guidelines

Introduction

The Responsible Disclosure Guidelines describe how AIB will engage with parties who identify and report potential security vulnerabilities relating to Allied Irish Banks, p.l.c. (AIB). 

At AIB, the security and the protection of our customer’s data is of utmost importance. We are committed to maintaining a secure environment and continuously improving our systems. If you believe that you have discovered a security vulnerability or issue in any platform or service owned or operated by AIB, we encourage you to notify us.

The Responsible Disclosure Guidelines apply to any digital assets owned or operated by AIB, including but not limited to websites, mobile applications, Application Programming Interface(s) (APIs), and other services. The Responsible Disclosure Guidelines are intended for individuals or organisations who discover security vulnerabilities. 

How to Notify Us

If you believe you have discovered or identified a security vulnerability or issue in any of the AIB’s systems, please send a notification to us promptly via email to our designated email address responsibledisclosure@aib.ie. Your submission will be reviewed and validated by a designated member of our security team. 

Please include the following information in your notification:

a. Your name and contact details for further correspondence.

b. The nature and type of the vulnerability you have identified.

c. The service / application impacted by the vulnerability.

d. Steps to reproduce the issue.

e. Potential impact.

f.  Any relevant screenshots, logs or code snippets.

g. IP Address from which the vulnerability was identified, together with the date and time of identification.

Guidelines for Reporting

It is important that you follow the guidelines below when reporting any security vulnerabilities:

1. Ensure that your actions do not negatively impact AIB, its customers, or its operations.

2. Do not access, modify or delete data that does not belong to you (without authorisation).

3. Do not disrupt any systems or services.

4. All disclosures should be made in accordance with the Responsible Disclosure Guidelines. It is important that the details of your findings remain confidential and are not shared with third parties other than AIB’s security team, to enable AIB to identify and address any security vulnerability that has been raised.

5. Do not perform any testing that could disrupt AIB’s services or systems.

6. Please ensure that you comply with all laws or regulations.

Any failure to follow the Responsible Disclosure Guidelines could expose AIB, its customers or other parties to material risk and lead to regulatory, reputational or financial harm. If you engage in any activities that are inconsistent with the Responsible Disclosure Guidelines or any applicable laws or regulations, you may be subject to legal action.

The following types of vulnerabilities are not in scope of these Responsible Disclosure Guidelines and should not be reported: 

  • Pivoting, scanning and vulnerability exploitation.
  • Exfiltration of data from AIB’s systems.
  • Email spoofing and social engineering of AIB’s customers and staff.
  • Fingerprinting/banner disclosure related issues.
  • Clickjacking and issues only exploitable through clickjacking.
  • Low impact/anonymous user CSRF.
  • Lack of security attributes on cookies.
  • Brute forcing.
  • Distributed denial of service attacks and denial of service attacks.
  • Rate limiting.
  • Username/email enumeration.
  • Misconfigured HTTP Security headers.
  • SSL related issues.
  • Vulnerabilities affecting users of outdated browsers.
  • UI Bugs, UX bugs, and spelling mistakes.
  • Theoretical security issues with no realistic exploit scenarios or attack surfaces.
  • Issues related to email misconfigurations.
  • Physical attacks such as office access.

What to Expect:

Upon receiving your submission, AIB will:

1. Acknowledge receipt of your submission within a reasonable timeframe.

2. Investigate and assess the reported vulnerability to determine its validity and impact.

3. Provide feedback to you, if possible, about the status of the vulnerability and any actions taken.

AIB does not offer reward programmes for reporting vulnerabilities. We appreciate the efforts of the security community in helping us to maintain the safety and security of our systems. Your responsible disclosure of vulnerabilities is invaluable to us.

For any questions or to report a vulnerability, please contact our security team at: responsibledisclosure@aib.ie

NOTE: AIB reserves the right, in its sole discretion, to modify the terms of the Responsible Disclosure Guidelines at any time.