Eurofins takes cybersecurity seriously and values the contributions of the security community and security researchers. We are committed to engaging with anyone reporting security vulnerabilities in a positive, professional, mutually beneficial manner that protects the Eurofins Group and our customers.
Eurofins operates a coordinated disclosure policy for disclosing vulnerabilities and other security issues. If you are aware of a security vulnerability that could affect the Eurofins Group or any of our assets, please contact us via the link disclosed under "How to Report a Security Vulnerability".
Eurofins runs a Hall of Fame where we express our sincere thanks to security researchers who ethically report security issues to us. You can find our Hall of Fame here.
Prior to reporting, please review the below items for program rules, in and out of scope vulnerabilities/applications.
When reporting vulnerabilities, please consider the attack scenario / exploitability (likelihood), and possible security impact of the bug. The following issues are considered out of scope:
Under very rare conditions Eurofins might consider specific submissions out of scope or not qualifying for a valid vulnerability, based on internal knowledge (e.g. risk acceptance) or based on duplicate internal/external submissions.
You can submit a security vulnerability via this form. Please remember to adhere to the preceding rules of engagement and submit as much information as possible to allow us to reproduce and validate your finding.
Thank you for helping keep Eurofins and our customers safe!