2026 Gauteng e-Panic Button — unsecured DB exposed crime reports, locations, OTPs
Data compromised
Crime-report text and categories (incl. domestic violence/assault); uploaded images (5,000+); GPS + location histories (coords, direction, speed, battery); names, gender, age, phones, emails, vehicle regs; login OTPs tied to cellphone numbers (GroundUp Sep 23–28)
Technical writeup
Verified responsible-disclosure incident — GroundUp (Joel Cedras, Sep 23, 2026) reported that Gauteng’s e-Panic Button emergency/crime-reporting app left its backend database accessible without proper controls. Exposed data included crime reports (domestic violence, assault, theft, drugs), 5,000+ report images, user account fields (name, gender, age, phone, email, vehicle registration), GPS at report time plus historical location tracks, and SMS OTPs stored alongside cellphone numbers. GroundUp alerted Gauteng e-Government and integrator Evolve VAS on Sep 21; Evolve accepted help and patched swiftly. Department-cited downloads ~180,000 (used as best available scale; not a forensic person census of confirmed access). Follow-up Sep 28: DA to report to Information Regulator; province had not notified affected residents. companyConfirmed true (vendor remediation + provincial ownership of the app).
Root cause
Unsecured application database / API exposure on the provincial e-Panic Button platform (GroundUp responsible disclosure; integrator Evolve VAS patched after Sep 21 alert)
References
- https://groundup.org.za/article/gauteng-panic-app-exposes-crime-reports-users-locations/
- https://groundup.org.za/article/people-exposed-by-gauteng-panic-app-data-breach-still-not-informed/
- https://dagauteng.org.za/2026/09/da-to-report-e-panic-button-data-breach-to-information-regulator-of-south-africa