Hello Researchers,
We are currently seeking additional testing around potential vulnerabilities that could result in unauthorised access to customer order information across our ParknShop and Watsons Hong Kong (WatsonsHK) digital platforms.
We encourage testing focused on identifying issues that could expose order-related data to customers who should not have access to it, including but not limited to:
- Access to another customer's order details
- Insecure Direct Object References (IDORs)
- Broken authorisation controls
- Order history disclosure
- Exposure of delivery information, contact details, or purchase information
- Enumeration of order identifiers leading to information disclosure
- API endpoints that return order data belonging to other customers
We are particularly interested in findings that demonstrate cross-account access to order information or other weaknesses that could impact customer privacy.
Valid reports showcasing impact on customer order details are eligible for a 25% bonus! This will be active from now until the end of September 2026.
Out of Scope for This Campaign
Please note that this research focus does not include compromised customer accounts or leaked credentials. Reports that rely solely on the use of valid username/password combinations obtained through credential stuffing, data breaches, password reuse, or other credential leakage sources are outside the scope of this request.
As always, please ensure testing is conducted safely and in accordance with our programme rules.
We appreciate your continued efforts in helping us protect our customers and services.
Thank you, AS Watson Group Security Team
Hi Hackers,
A new Tier 4 domain has been added to the scope:
id-watsonsbesti.com
This is an AI Chatbot integrated with the Watsons Indonesia e-commerce website: www.watsons.co.id.
Happy Hacking!