South Africa: How Gauteng's New Panic App Exposed Your Data
[GroundUp] Reports about domestic violence and assault, including images and locations, could be accessed by a tech-savvy computer user
Reports of domestic violence, assault, theft and drug crimes were accessible through the Gauteng government's e-Panic app. This South African application allowed residents to report crimes and request emergency assistance. However, the app's database was not properly secured, exposing users' personal data, criminal reports, uploaded images, and location data.
GroundUp, a non-profit investigative organization, discovered this by analyzing the app and its connections. The exposed data included users' names, gender, age, phone numbers, email addresses, and vehicle registration numbers. Images uploaded by users related to crime reports were also accessible, as were crime descriptions that sometimes named alleged perpetrators.
Every crime report included GPS coordinates, and location histories with details about direction, speed, and battery information were also exposed. This could potentially reveal where a person had been moving, rather than just where they pressed an emergency button. The app's background location feature, which requested access even when not in use, further increased the risk of location data exposure.
The e-Panic website claimed to use administrative, technical, and physical security measures to protect users' personal information. However, the actual situation contradicted these assurances. The app processed user data, including location, photos, and contact information, despite claims that no data was collected or shared. The app interacted with multiple services, including Discord, a gaming-focused chat app, which raised questions about the necessity of these connections.
The Gauteng government marketed the e-Panic Button as a means for residents to access private armed response and medical emergency services. The app had gained over 100,000 downloads on Android, with the Department of e-Government claiming more than 180,000 downloads by August. The government gave the developers 24 hours to address the security vulnerabilities or take down the app.
After this deadline passed with no response from the government or the developers, it became clear that significant security issues were present, but they should not have existed in the first place.
Written by urgent.news from AllAfrica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.