← Gauteng Department of e-Government

2026 Gauteng e-Panic Button — unsecured DB exposed crime reports, locations, OTPs

2026 180.0K records affected Share on X

Data compromised

Crime-report text and categories (incl. domestic violence/assault); uploaded images (5,000+); GPS + location histories (coords, direction, speed, battery); names, gender, age, phones, emails, vehicle regs; login OTPs tied to cellphone numbers (GroundUp Sep 23–28)

Technical writeup

Verified responsible-disclosure incident — GroundUp (Joel Cedras, Sep 23, 2026) reported that Gauteng’s e-Panic Button emergency/crime-reporting app left its backend database accessible without proper controls. Exposed data included crime reports (domestic violence, assault, theft, drugs), 5,000+ report images, user account fields (name, gender, age, phone, email, vehicle registration), GPS at report time plus historical location tracks, and SMS OTPs stored alongside cellphone numbers. GroundUp alerted Gauteng e-Government and integrator Evolve VAS on Sep 21; Evolve accepted help and patched swiftly. Department-cited downloads ~180,000 (used as best available scale; not a forensic person census of confirmed access). Follow-up Sep 28: DA to report to Information Regulator; province had not notified affected residents. companyConfirmed true (vendor remediation + provincial ownership of the app).

Root cause

Unsecured application database / API exposure on the provincial e-Panic Button platform (GroundUp responsible disclosure; integrator Evolve VAS patched after Sep 21 alert)

References