The Gauteng provincial government in South Africa has assured residents that its e-panic button app, used to report emergencies and crimes, has had its data security flaws patched after a breach was discovered. University computer science students found the flaws while analyzing the app's code last week. The app, launched in July 2024, had 288,307 active users registered on the system, who had logged 114,414 emergency call-outs, resulting in the reporting of 59,394 crimes.

Joel Cedras, one of the students who exposed fraud within the South African Social Security Agency database in 2024, reported that he was easily able to access the personal information of Gauteng e-panic button users. Cedras conducted a static analysis of the app's code and noticed that the database storing user information was unauthenticated and accessible to anyone with a basic understanding of the framework. This raised concerns about the security of sensitive information, including user addresses, ID numbers, license plate numbers, contact details, and details of the crimes reported by users.

The Gauteng e-government department stated that the platform is part of the government's commitment to harness technology to strengthen public safety, improve access to emergency services, and ensure that residents can summon assistance quickly during moments of crisis. The department revealed that it had collected a significant amount of data since the app's official launch, with a substantial number of active users and emergency call-outs logged. However, Cedras' findings contradicted the department's claims of having robust security measures in place.

According to Cedras, the privacy policy on the site states that all data is encrypted, but he found that none of the information was encrypted. He was able to access sensitive information, which raised concerns about the potential for misuse. The department, however, assured users that tighter cybersecurity protocols would be implemented in the future to prevent similar breaches.

The department said it had "identified an attempted security breach" of the app and that an average IT professional could not have carried it out. The incident involved a highly specialized organization with advanced cybersecurity expertise and capabilities in vulnerability identification and security testing. However, Cedras' comments contradict the department's view of who alerted them to the app's security flaws, stating that they alerted the department via email.

The Democratic Alliance (DA) has expressed concerns over the security breach and announced plans to report the matter to the Information Regulator. The DA's Gauteng spokesperson for e-government, Michael Waters, demanded that the department appear before the e-government portfolio committee to explain the breach. Waters highlighted the province's crime crisis and the need for residents to trust that their information will be protected.

The Gauteng e-government department has assured residents that no citizens' personal information was compromised during the breach. The department has patched the digital holes in its app and is implementing tighter cybersecurity protocols to prevent future breaches. Residents are still being urged to utilize the e-panic button app, which has been a crucial tool in reporting emergencies and crimes in the province.

Key points

  • The Gauteng e-government department has assured residents that the e-panic button app data is secure after a security breach was discovered.
  • University computer science students found flaws in the app's code, allowing access to sensitive user information.
  • The Democratic Alliance plans to report the matter to the Information Regulator and demands that the department appear before the e-government portfolio committee.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.