Inti De Ceukelaire

Inti De Ceukelaire is a Belgian ethical hacker and Chief Hacker Officer at Intigriti, known for public security and privacy research including the Ticket Trick and the manipulation of a Donald Trump tweet.

8 News mentions

Overview

Inti De Ceukelaire is a Belgian ethical hacker and internet entrepreneur, born on 14 May 1995 in Aalst. He is Chief Hacker Officer at Intigriti, a European vulnerability disclosure platform that was founded in 2016 by Stijn Jans, who runs it as CEO, has more than 100 employees and offices in the United Kingdom, the United States, the Netherlands and South Africa. His public work centres on security and privacy demonstrations. In 2017 he bought an expired domain name and used it to place a carnival video from Aalst inside a tweet by Donald Trump, obtained Melania Trump's private email address through a Facebook function, and published a Facebook Graph Search tool later renamed StalkScan. The same year he documented the Ticket Trick, a technique that abuses helpdesk and issue tracker systems that trust every email address on a given domain, which PortSwigger ranked third in its Top 10 Web Hacking Techniques of 2017. Later projects include benikerbij.be in 2021, letting Belgian users check whether their phone number was in the leak of 533 million Facebook records, and research in 2022 into parking applications that made drivers traceable by licence plate, in which he located 29 percent of the cars of 120 participants.

De Ceukelaire appeared in 2016 in the television programme Opgejaagd on VIJF, where he and Dutch presenter Jan Kooijman exposed cyberstalkers and catfish profiles. He worked as a web editor at Studio Brussel until 2018, and then became a partner in Intigriti. In August 2018 he won the Most Valuable Hacker award at HackerOne's live hacking event in Las Vegas. He received the IT Person of the Year award from Computable in 2020, and in December 2023 he was named Young Cyber Security Professional at Belgium's Cyber Security Awards, run by the Cyber Security Coalition. Since 2021 he has toured with a lecture called Hackefietjes. His reporting has continued alongside the Intigriti role. In 2019 he ran stap twee, donating two euro to Stichting tegen Kanker for every person who switched on two step verification, and showed that Facebook's search algorithm surfaced photos of women in bikinis. In 2018 he flagged a security problem at personality quiz publisher Name Tests, for which Facebook paid out under its data abuse programme, and used a modified link to make the Vatican website appear to show Pope Francis declaring Aalst a holy city. In May 2024 he published research in which he bought more than 100 expired domain names of Belgian social welfare and justice institutions and found sensitive citizen data still being sent to them. In August 2025 he analysed how Orange Belgium communicated about a breach affecting 850,000 customers.

As Chief Hacking Officer, Inti leads the hacker community strategy at Intigriti, representing the ethical hacker perspective and driving engagement with the platform's researcher community.

Career history

  1. IntigritiCurrent

Media & appearances

  • Infosec Studio by IWYouTube
    Reading RFCs for Hacking | IWCON-W22 Talk by Inti De CeukelaireInti De Ceukelaire discusses how reading RFC documentation is underestimated as a hacking technique, explaining that he prioritizes reading documentation and infrastructure details during live hacking events before even opening his computer, as this often reveals vulnerabilities and helps him understand developer decisions. He shares his background as a bug bounty researcher since 2011 who has reported over three hundred vulnerabilities, primarily focused on privacy, anonymization attacks, and web applications, and expresses optimism about the future of hacking tools and automation.
  • Orchid LabsYouTube
    The World of Ethical Hacking and Cybersecurity with Inti De Ceukelaire, Head of Hackers at IntigritiInti De Ceukelaire discusses his early entry into hacking, beginning with cheating in video games as a child and discovering a vulnerability in the PlayStation Portable at age 15 through experimentation with the browser bookmarks. He explains that he posted this vulnerability to a private forum rather than reporting it to Sony, since companies at that time had no formal vulnerability disclosure processes and were known to pursue researchers.
  • Critical Thinking - Bug Bounty PodcastYouTube
    Inti De Ceukelaire: Hacking your way into Metallica (Ep. 33)In this podcast episode, Inti De Ceukelaire discusses his experience with live hacking events, particularly his reputation for consistently delivering creative and engaging show-and-tell presentations that earned him recognition for the most innovative bug demonstrations at these events. He also explains how his early participation in the live hacking circuit, starting as a plus-one to a DC event where he placed eighth, led to invitations to subsequent events in San Francisco and beyond, with show-and-tell becoming a key element of his involvement in the hacking community.

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.