- Premium Content It takes our newsroom weeks - if not months - to investigate and produce stories for our premium content. You can’t find them anywhere else.
The stunning rise of India’s ethical hacking industry
Ever since he can remember, Amol Baikar has been fascinated with how things work. A resident of Pune, a cosmopolitan city a few hours from Mumbai, his inquisitiveness now extends to the intangible workings of the internet.
While tinkering around last December, Baikar found a security flaw in a popular sign-in option of social media giant Facebook.
It was a serious vulnerability in its “Log in with Facebook” feature, one that could allow any hacker worth their salt to access anyone’s Facebook account.
The tech giant patched up the error after Baikar had reached out to them. But he found a way around the fix, prompting the company to correct it a second time around.

Image credit: Siddharth Bishnu
This March, Facebook awarded US$55,000 to Baikar for reporting the security flaw – an amount that is almost enough to buy an apartment in the city of his residence.
That said, the 29-year-old didn’t stumble upon Facebook’s vulnerability; he was out looking for one. Baikar has done this several times before, and he’ll do it again. That’s what he does as an ethical hacker a.k.a. a (cyber)security researcher or a white hat hacker — all names used to call the antithesis of a black hat hacker.
Baikar is far from being alone in looking for software bugs.
Today, tens of thousands of young Indians are neck-deep in the world of cyberthreats, eyes glued to the screens and jabbing away at their keyboards in search of bugs. And some companies pay considerable amounts to these ethical hackers, many of whom have made a career out of bug hunting.
This year, Facebook awarded its highest bug bounty payout ever, giving out almost US$2 million for 1,000 reports it found credible in 2020 – a figure that has risen for the last three years. India is among the top three countries that won the biggest amount from the pool.
The exact numbers vary, but all reports indicate the dawn of international cybersecurity powered by bug bounty hunters in India.
HackerOne, which has ethical hackers from 170 countries on its platform, says that at least 160,000 of these hackers are from India. The country was also among the top five geographies in terms of bounties earned last year.
On the platform, over 200 Indians have earned US$10,000 or more in bounties, and approximately 100 have earned US$25,000 or more, says HackerOne.
According to crowdsourced security firm Bugcrowd, the number of bug bounty hunters from India on its platform grew by 83% this year. Other countries in its top five are the US, Pakistan, Bangladesh, and Indonesia.
Winds of change
In the beginning, there was a bug
Sunny side up
Halls of glory
Dawn of the bounty hunters
Stay ahead in Asia’s tech landscape
This is premium content. Subscribe to read the full story.
Young cyber enthusiasts from India are increasingly striking gold and making a recession-proof career by hunting bugs for tech giants
We know this is not ideal. ⌛ Sign up in 20 seconds. Cancel anytime.
Our subscriber community includes professionals from these companies:





Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.