← Blog

Gauteng e-Panic App Exposed Crime Reports and GPS

Share on X

Gauteng’s e-Panic Button app — marketed as a way for residents to report crime and summon private armed response or medical help — left its backend database open enough that a journalist could read crime reports, GPS trails, uploaded photos, and even login OTPs. GroundUp’s Joel Cedras published the findings on September 23, 2026, after alerting the provincial Department of e-Government and integrator Evolve VAS on September 21. Evolve patched quickly. The province, a week later, had still said almost nothing to the people who filed domestic-violence and assault reports into that system.

This is a verified Gauteng e-Panic data breach: responsible disclosure, vendor remediation, political oversight demands, and a regulator escalation path. Canonical record: https://breachhistory.com/gauteng-e-government/gauteng-epanic2026 (/gauteng-e-government/gauteng-epanic2026). BreachHistory indexes ~180,000 downloads as the department-cited scale of the user base — not a forensic count of confirmed unauthorized downloads.

What GroundUp found

The app’s database exposed:

  • Crime report text, categories, and descriptions — including domestic violence and assault
  • More than 5,000 crime-report images
  • User account fields: name, gender, age, phone, email, vehicle registration
  • GPS at report time and location histories with direction, speed, and battery data
  • Six-digit OTPs stored next to cellphone numbers used for login

GroundUp’s method matters for the record: reporters analyzed what the app connects to. They state they broke no laws and did no “hacking” — a tech-savvy user could replicate the access. That framing still meets BreachHistory’s bar for an attested exposure: the data was reachable, the owner’s vendor accepted the finding, and fixes landed.

Of the first 100 crime reports examined in the follow-up piece, 11 concerned domestic violence and eight assault. Connecting a survivor’s name, phone, and live location history to an alleged perpetrator’s name in the same report is not a theoretical privacy failure. It is a physical-safety failure.

Timeline

  1. 2024 — e-Panic platform birth; location history in the exposed store went back to launch.
  2. March 2024 — Evolve VAS among bidders; later integrator on the platform (contract figures disputed in press: early R10m listing vs department R269m total cited later).
  3. Noon, 21 September 2026 — GroundUp emails Gauteng e-Government and Evolve; 24-hour fix-or-take-down window; offers assistance.
  4. Hours later — Evolve accepts help and documents remediation steps; vulnerabilities appear fixed.
  5. 23 September 2026 — GroundUp publishes the exposure story; province silent.
  6. 28 September 2026 — DA says it will report to the Information Regulator; still no resident notifications from the department.

Aura, the emergency network behind several private SOS apps, told MyBroadband it had not supported Gauteng e-Panic for over a year. The app code later pointed at Trigger Systems. Vendor churn on a panic button that stores DV reports is a governance story as much as a crypto story.

What we still do not know

  • Exact number of unique users exposed — downloads ≠ active accounts ≠ confirmed exfiltration.
  • Whether hostile parties copied the database before the Sep 21 fix — access logs and independent review still demanded by the DA.
  • When (or if) POPIA notifications to affected residents will go out.
  • Full contract accountability — R269-million platform spend cited via legislature reporting vs earlier tender snippets.

Why OTP exposure breaks the whole login model

GroundUp found OTP records named by cellphone number, with creation time and used/unused flags. That defeats SMS as a second factor: anyone who can read the table can request a code and then lift it from the same store. Pair that with exposed phones and emails and you have account takeover on an app that tracks people’s movements.

The ePanic website’s claim of end-to-end encryption and PII obfuscation did not match what reporters saw. Google Play’s “no data collected” declaration contradicted the app’s own permissions and backend behavior. Apple’s listing was more honest about location and contact collection. Those contradictions are not cosmetic — they are how users get lied into a false sense of safety.

Who is at risk

Anyone who filed a crime report through e-Panic — especially domestic violence and assault reporters — should assume names, narratives, photos, and locations may have been visible to strangers for an unknown window.

People named as alleged perpetrators in those reports also appear in the exposed material, with different but real risks (vigilantism, doxxing).

Users who only installed the app for emergencies still had account fields and possibly location histories in the store. Department messaging cited ~180,000 downloads.

Private armed-response partners tied into the ecosystem should review whether their own consoles inherited the same data plumbing.

South African government data-failure context

GroundUp framed e-Panic as another state IT fiasco in a country where emergency numbers already struggle for public trust. Building a R269-million parallel panic stack instead of fixing 10111 is a policy argument; leaving DV reports on an open database is a security fact. The DA’s Michael Waters called it the second sensitive-information failure involving Gauteng Provincial Government systems and pushed for Information Regulator action under POPIA.

Related BreachHistory context on large South African political data claims: ANC Black X 2.3M claim and ANC timeline blog. Different mechanism (leak vs misconfiguration), same citizen-trust damage.

What Evolve and Gauteng did — and did not do

Evolve’s response is the rare vendor chapter worth praising on process: accept the reporter’s help, patch fast, write down what changed. Gauteng’s silence is the other chapter. Nearly a week after publication, GroundUp said the province had not told affected residents whether they would be notified. Information Regulator guidance expects compromise reporting and resident notice after assessing what was accessed.

Residents should not wait for a perfect government SMS. If you used e-Panic for a sensitive report, assume exposure and plan personal safety accordingly — change routines that the location history could reveal, and be wary of anyone contacting you “about your case” with details only the database held.

Action items

  1. Update the app or remove it until the department publishes a clear security statement.
  2. Change related passwords/emails if you reused the e-Panic email elsewhere.
  3. Treat unexpected “police / armed response” calls that cite your report details as hostile until verified.
  4. If you filed a DV report, speak with a trusted advocate about safety planning given possible location exposure.
  5. Preserve screenshots of any suspicious contact for the Information Regulator complaint process.
  6. Do not download “e-Panic breach check” APKs from random links — that is how a second compromise starts.

Canonical record and sources

Catalog entry: Gauteng e-Panic Button exposure 2026.

Related catalog: DoD DMDC ~3M, NC AOC IDOR, Fort Smith Interlock claim.

Emergency apps and the duty to minimize

Panic apps argue that continuous location is required for response. GroundUp’s distinction is the right one: collecting location for responders is not the same as leaving years of tracks on an internet-reachable store. Retention back to 2024, OTP tables beside MSISDNs, and crime photos without access control fail basic POPIA-style minimization even before a journalist arrives.

Other provinces watching Gauteng should inventory every SOS and tip-line app for the same failure mode: public or weakly authenticated APIs that return full case objects. The e-Panic Button data breach will be cited in tender fights for years. The people who filed reports needed protection the week the database was open — not a press release after the DA filed with the regulator.

Was I affected? If you downloaded Gauteng e-Panic and created an account, treat yourself as in-scope until the department proves otherwise with logs. Downloads near 180,000 set the upper bound of the conversation; the lower bound is every domestic-violence report GroundUp sampled in the first hundred.

BreachHistory will update the catalog if the Information Regulator publishes findings, if Gauteng issues resident notices with a headcount, or if access-log reviews confirm hostile copying. Until then, the attested story is an unsecured emergency database patched after public-interest research — and a province that was slow to speak to the people inside it.

Comparing e-Panic to classic IDOR and open-bucket failures

Functionally this rhymes with object-level authorization bugs and open cloud buckets: a client can reach objects it should not. GroundUp did not need a zero-day. Provincial apps that grow through cascaded vendors (Aura out, Trigger in, Evolve integrating) accumulate trust assumptions. Each handoff is a chance to drop an authz check. Budget for adversarial review of emergency apps the same way you budget for load testing — before the first DV survivor trusts you with a photo.

For BreachHistory readers outside South Africa, the portable lesson is product honesty. If Google Play says “no data collected” while the binary requests background location and writes crime photos to a server, users cannot make informed consent. Store listings are part of the security boundary.

Further reading on government identity exposures in the BreachHistory catalog includes jury and court IDOR-style failures such as North Carolina AOC and municipal ransomware claims like Fort Smith. Different continents, same pattern: civic apps collect sensitive citizen data faster than they ship access control. Gauteng’s e-Panic Button was supposed to make people safer on the street. An open database of their movements and DV narratives does the opposite. Hold the department to POPIA notice duties; hold integrators to secure-by-default API design; hold app stores to accurate data-safety labels.

If you are a councillor or MPL reading this after the DA filing, ask for three artifacts in the oversight hearing: the access logs for the week before September 21, the list of IP addresses that queried crime-report objects at volume, and the draft resident notice. Without those, “we fixed it” is incomplete. Survivors deserve better than silence.

Domestic violence data on an open API is a safety incident

Most breach writeups obsess over credit freezes. Freezes do nothing for a survivor whose GPS trail and case narrative sat on an unsecured store. The Gauteng e-Panic Button exposure is closer to a witness-protection failure than to a retail password dump. Location histories that include speed and direction can reveal shelters, workplaces, and school runs. Crime-report images can reveal faces, injuries, and home interiors. OTPs can let an abuser who knows a phone number hijack the app identity used to call for help.

That is why the DA’s push to the Information Regulator matters, and why provincial silence reads as negligence to the people inside the dataset. Patching the hole is necessary and insufficient. Notification, log review, and safety guidance have to follow.

How emergency-app tenders go wrong

Press figures around the platform — early R10-million tender snippets versus later R269-million total contract talk, with R131.3-million already paid to Evolve across years — will fuel opposition politics. Security engineers should extract a narrower lesson: high spend does not buy authorization checks. Require penetration tests that specifically attempt unauthenticated reads of case objects before go-live. Require data-retention schedules that delete location history when the emergency closes. Require OTP stores that are hashed, short-lived, and never listable by MSISDN.

Aura’s exit and Trigger Systems’ appearance in code show how continuity of security ownership dissolves across vendor changes. Every handoff needs an access-control regression test. Without it, you inherit an open table and a marketing site that still claims encryption.

POPIA duties in plain language

South Africa’s Information Regulator expects organisations to report security compromises and to tell affected people. GroundUp notes that guidance applies across risk levels and that bodies must establish what was accessed and how many people were touched. A week of provincial non-response after a public fix is not a gray area — it is a missed duty from the perspective of the people who filed reports.

Residents can still document their own exposure concerns and follow DA / regulator complaint channels. Do not let the absence of an SMS lull you into assuming you were outside the database.

International parallels worth bookmarking

Misconfigured civic apps show up worldwide. Court and jury portals with IDOR bugs, municipal ransomware crews copying resident files, and military HR file shares left open for months — including the Pentagon DMDC ~3 million notices — rhyme with e-Panic’s failure mode: sensitive identity data collected for a legitimate mission, then stored without commensurate access control. The mission does not excuse the storage.

If you build SOS products for other African metros, treat GroundUp’s September series as mandatory reading in your next sprint planning. Copy the disclosure response Evolve got right. Do not copy the data-safety labels Gauteng’s stores got wrong.

Editorial continuity note for BreachHistory readers: this post is part of the October 1, 2026 catalog refresh that also tightened counts on MedImpact (~327,082 in Oregon AG-facing aggregation) and refreshed Pentagon DMDC field inventory from BleepingComputer’s October 1 coverage. Cross-linking those rows is deliberate — healthcare PHI, emergency-app location data, and military personnel SSNs are different domains that fail in the same way when authorization is an afterthought. Keep the canonical incident URLs in your notes rather than screenshot chains that omit the “what we still do not know” sections. Updates will land on those URLs when regulators, hospitals, or departments publish censuses and root-cause memos. Until then, act on the attested facts: patient samples and a $100k demand in Hyderabad; an open panic-button database in Gauteng; and millions of DoD personnel letters already in mailboxes in the United States.

Finally, share the official hospital or provincial channels with family members who are less online. Most secondary harm after medical and emergency-app breaches happens to people who never read the original investigation. A forwarded official URL beats a viral WhatsApp rumor. If you are a journalist localizing this story, cite GroundUp and Hyderabad Mail primary pieces, avoid Breachsense, and say clearly when a headcount is missing. Precision is part of harm reduction.