A recent investigation by GroundUp revealed that the Gauteng government's e-Panic Button app had exposed sensitive user data, including crime reports, locations, and personal details. The app, designed to allow residents to report crimes and request emergency assistance, had an unsecured database that made it possible for anyone to access this information. The exposed data included names, gender, age, phone numbers, email addresses, and vehicle registration numbers of users.

The investigation found that the app exposed reports alleging domestic violence, assault, theft, and drug-related crimes, as well as images related to these crimes. The reports sometimes named the alleged perpetrators, and the app's GPS coordinates and location histories were also accessible. This information could be used to identify users who made reports and those accused of committing crimes. The exposed data also included login codes and other sensitive information.

The Gauteng government's e-Panic Button app had been downloaded over 180,000 times, with more than 100,000 downloads on Google Play alone. The app's Google Play page stated that no data was collected and no data was shared with third parties, contradicting the app's actual functionality. Apple users, on the other hand, were informed that location, physical address, email address, name, and phone number may be collected and linked to a user's identity.

GroundUp alerted the Gauteng government and the IT company responsible for the app to the problems on Monday, and they were fixed within 24 hours. The company, Evolve, sent a detailed email explaining the actions taken to rectify the situation and thanked GroundUp for bringing the issues to their attention. However, the incident raises concerns about the security and privacy of users' data.

The e-Panic Button app's database contained location histories, including coordinates, direction, speed, and battery information, which could reveal users' movements over time. The app also requested permission to access users' locations even while running in the background, and users were asked to agree to sharing their live location. This extensive use of background location and sensitive data collection raises questions about the app's security measures.

The Gauteng government's website claimed that the app used administrative, technical, and physical security measures to protect personal information, including end-to-end encryption and obfuscation of personally identifiable information. However, GroundUp found no evidence of such measures. The Information Regulator was also notified of the incident, but no response was received.

The incident highlights the importance of securing sensitive user data, particularly in apps that handle emergency requests and crime reports. While Evolve acted swiftly to fix the vulnerabilities, the incident raises concerns about the app's design and security measures. The Gauteng government and Evolve must ensure that users' data is protected and that the app is secure for continued use.

Key points

  • The Gauteng government's e-Panic Button app exposed sensitive user data, including crime reports, locations, and personal details, due to an unsecured database.
  • The app had been downloaded over 180,000 times, and the incident raises concerns about the security and privacy of users' data.
  • The Gauteng government and Evolve must ensure that users' data is protected and that the app is secure for continued use.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.