Enterprise

This hacker makes an extra $100,000 a year as a 'bug bounty hunter’

Read in app
HackerOne Jobert Abma
HackerOne cofounder Jobert Abma  HackerOne Jobert Abma

Jobert Abma, the 25-year-old cofounder of a hot startup called HackerOne, has been breaking into computers since he was 13.

And he's been been getting into hacking scrapes with his cofounder and best friend Michiel Prins for almost as long.

Growing up in the Netherlands, Abma gave Prins an unusual graduation present: the user name and password to a local TV station that did a regular news broadcast about the school.

The duo then took control of the TV station and ran their own broadcast on live TV instead.

"The TV station was not amused," Abma tells Business Insider.

The teachers blamed Prins, who was a year older than Abma, for the hack, and "he never told them that I was to blame," Abma says. Prins wound up having to do 25 hours of community service washing windows, but "that’s what best friends are for." 

The two were so good at hacking that Abma's internet provider noticed. It sent a letter to his parents saying, "We think you have a virus installed on your computer because there's all this weird traffic coming from your systems. My parents were like, 'We don’t have a virus. We have a son,'" Abma recalls.

But the turning point for the pair came when they were in college together at Hanze University of Applied Sciences in the Netherlands.

During Abma's freshman year, the two were looking into the software the school used to manage homework assignments and grades. They found a hole that allowed them to access everyone's grades.

HackerOne cofounder Michiel Prins
HackerOne cofounder Michiel Prins  Linkedin/Michiel Prins

They told the software vendor about the hole and never heard back, Abma recalls. (As a rule, software companies don't automatically respond to every unknown person who contacts them claiming to have found a bug.)

So they reported the hole to the university. The school contacted the company and it fixed the hole. The university was so impressed, it hired the pair to do a bigger vulnerability test on that software for the university.

"We made so much money on that contract that we could pay for our college tuition," he says. "We were going to college and at the same time working for the university."

Hanze loved their work and published their research.  The software company, he recalls was less than pleased. "We got a cease-and-desist letter." 

Making $10,000 a week in college

Because of all of this, and the potential trouble they could get in, "our parents forced us to start a company," he said.

But getting customers was a struggle at first. "As you can imagine, no one is going to trust two college kids with their security," Abma says.

HackerOne Jobert Abma
HackerOne cofounder Jobert Abma  HackerOne Jobert Abma

So, they came up with a challenge, telling prospects that if they couldn't break into the company within 60 minutes they would buy the whole company cake.

"But if we can hack into the company, then we want to have a meeting and talk about what was wrong and see how we can help you," he says.

People loved the cake challenge. "We spent our nights and weekend hacking and it was the best introduction we ever had to a lot of big companies in the Netherlands," he says.

Soon they had contracts from the government, large banks, and insurance companies. 

"That was a very exciting time. We were 19 and 20 years old. And we were making roughly $10,000 a week just the two of us," he says. "For two college kids, that was a very large amount of money."

Inspiration for HackerOne

With this background, the two moved to San Francisco and cofounded HackerOne along with Merijn Terheggen and Alex Rice, the former head of product security at Facebook.

I know someone who is going for $500,000 this year as his personal goal. He’s capable.

HackerOne is a website where companies can ask hackers to attack them, and then pay fees based on the holes found. The scarier the hole, the bigger the fee. (HackerOne takes a 20% cut.)

These are called "bug bounty" programs. 

The idea is to put good-guy hackers on the company's payroll so they can find problems before the bad guys do.

Many big tech companies run their own bug bounty programs, like Facebook, Google, Microsoft, Mozilla, Uber, Yahoo.

But HackerOne gives any company access to a screened pool of qualified, safe hackers. It also offers software that allows them to manage any software holes the hackers find so they can fix them. Its customers include everyone from big tech companies to startups, including the Department of Defense, GM, Slack, Twitter, Yahoo, and Uber.

$7 million in bounties paid

HackerOne has helped companies discover 21,000 verified vulnerabilities since it was founded in 2012 and it has paid out over $7 million in that time, it says.

HackerOne CEO Marten Mickos
HackerOne CEO Marten Mickos  HackerOne

It's growing like crazy as companies realize the value of having access to their own friendly army of hackers.

The startup has 500 customers and about about 50 employees and has raised $34 million in funding.

That means the amount of money hackers earn via the site is accelerating. For instance, it only took 12 weeks for hackers to earn the last $1 million worth of bounties. HackerOne had paid out $6 million in bounties in February and that number was up to $7 million by April.

HackerOne is not only bug bounty startup. Bugcrowd, CrowdSecurity, and Synack are some others.

However, HackerOne gained some notice when it landed Marten Mickos as CEO last year. He's well known in the software world a the former CEO of Eucalyptus and MySQL, and he sold both of those companies for big bucks — Eucalpytus 

An extra $80,000 this year

Even though Abma has a day job as a cofounder of HackerOne, he's still a hacker at heart.

HackerOne Jobert Abma
HackerOne Jobert Abma  HackerOne Jobert Abma

He still spends some nights and weekends participating in the bug bounty programs. Most companies pay between $500 and $1,000 per qualified hole found.

But fees can go far higher. Google, for instance, pays up to $20,000 for the nastiest bugs. Others pay even more.

Abma has made an extra $80,000 in the last 8 months on bug bounties, he says.

His goal is to earn an extra $100,000 in 2016, which he's on track to do, he says.

His average bounty is $4,000 per bug, with his largest payout being $30,000, he tells us. Those are some seriously nasty holes.

There are 2,600 hackers in the system who have found at last one qualified bug, HackerOne says, and Abma says he's not one of the top 100. He says he ranks in the top 3%.

That means that there are quite a few bug bounty hackers earning more.

"There are some hackers making $200,000 a year," Abma says, and about 20 making $100,000 annually, he says. "I know someone who is going for $500,000 this year as his personal goal. He’s capable."

Most of these hackers are not doing bounties as their full-time gig either, but they have "a normal day job. Most of them are in tech, they are a software engineer or do computer security. They do this as a second income. It's a very nice addition to most people’s salaries."

For Abma, it's all about helping companies while helping others earn extra money while enjoying the extra cash himself.

"I can buy an upgrade to business class when I travel, dine very luxuriously, and my wedding ring was slightly more expensive than I would otherwise be able to pay," he says.

"Some people use it to pay for their college tuition or to finance their mortgage. We're normal people and hackers are super important to the future of the internet," he says.

Read next

Julie Bort was Business Insider's Editor at Large for the Tech team. She loves investigating stories and shedding light on the tech industry's most amazing people.Here's a small sample of some of Julie's work.Former Pinterest employees describe a traumatic workplace where managers humiliate employees until they cry, Black people feel alienated, and the toxic culture 'eats away at your soul'Sex, tequila, and a tiger: Employees inside Adam Neumann's WeWork talk about the nonstop party to attain a $100 billion dream and the messy reality that tanked itInsiders say WeWork's IT is a patchwork of cheap devices and Band-Aid fixes that will take millions to fixWeWork's toxic phone booths were created in-house by its Powered by We business70-hour weeks and 'WTF' emails: 42 employees reveal the frenzy of working at Tesla under the 'cult' of Elon MuskElon Musk works so many hours at Tesla, employees are constantly finding him asleep under tables and desksHow this woman went from a Pizza Hut employee to a founder of a $4 billion startupAn Oracle insider explains how some salespeople gamed the system to sell more cloudTHE TAKEDOWN OF TRAVIS KALANICK: The untold story of Uber's infighting, backstabbing, and multimillion-dollar exit packagesMicrosoft is in talks to buy GitHub, a startup at the center of the software world last valued at $2 billionThe alarming inside story of a failed Google acquisition, and an employee who was hospitalizedInside Facebook's plan to eat another $350 billion IT marketHow a registered sex offender wound up living in an Airbnb hosting unsuspecting guestsA controversial ex-banker is the person who really runs Twitter — and he's gambling the company's future on one risky betSecret passages and skipped meals: Oracle's CEO gave us a rare peek at what it really takes to run a $37 billion companyHP told some employees to choose between becoming contractors with no benefits or being fired without severance'I felt like we were being extorted': Customer says Oracle tried to strong-arm him into a cloud saleHow the queen of Silicon Valley is helping Google go after Amazon's most profitable businessAirbnb host: A guest is squatting in my condo and I can't get him to leaveLIES, BOOZE, AND BILLIONS: How one of the fastest-growing startups in Silicon Valley history raised $580 million then spiraled out of controlGitHub is undergoing a full-blown overhaul as execs and employees depart — and we have the full inside storyWhen she's not writing for Business Insider, Julie can usually be found on the trails, on my mountain bike, or on my skis, if you know where to look.