YWH YesWeHack LIVE
Swiss Post
€50 –€10,000
Open on YesWeHack ↗
- listed
- before tracking
- tracked since
- 2026-09-20
- managed triage
- no
9 targets in scope
| asset | type | bounty | max sev | seen |
|---|---|---|---|---|
https://account.post.ch | domain | · | · | 2026-09-20 |
https://billingonline.post.ch/OnlinePayment/Web/v1/BOI | domain | · | · | 2026-09-20 |
https://service.post.ch/ekp-web/ | domain | · | · | 2026-09-20 |
https://service.post.ch/ele-klp/ele/ | domain | · | · | 2026-09-20 |
https://service.post.ch/zopa/app/ | domain | · | · | 2026-09-20 |
https://shop.post.ch/shop | domain | · | · | 2026-09-20 |
https://apps.apple.com/ch/app/die-post/id378676700 | mobile | · | · | 2026-09-20 |
https://play.google.com/store/apps/details?id=com.nth.swisspost&hl=de_CH&gl=US | mobile | · | · | 2026-09-20 |
(*.post.ch:80|*.post.ch:443) AND 194.41.128.0/17 | other | · | · | 2026-09-20 |
6 out of scope — black ICE, don't touch
Any services related to Incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))otherAny services related to PostCardCreator (for example https://service.post.ch/pccweb, mobile apps and https://pccweb.api.post.ch)otherAnything that has not been described as in scope in the previous section is automatically out of scope.otherAttacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes DNS, NTP, routers, systems of the ISP, etc.).otherPlease note that some of the applications may contain links or redirect you away from the URIs described in the scope section. This means you are leaving the scope if you follow these links / redirects.otherThe alternative login (https://login.swissid.ch) is out of scope. It also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scope.other
Change log
get alerts ↗No changes since we started tracking on 2026-09-20.