Skip to main content
Back
eThekwini Municipality

eThekwini Municipality

eThekwini Municipality

mediumHave I Been Pwned
Disclosed

September 7, 2016

3488 days ago

Records

81.8K

Confirmed

Root Cause

Phishing

Industry

Government

Description

In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior to launch containing passwords in plain text and the site allowed anyone to download utility bills without sufficient authentication. Various methods of customer data enumeration was possible and phishing attacks began appearing the day after launch.

View source
Exposed Data Types

Exposed Data

PasswordsGovernment IDsEmail AddressesPhone NumbersPhysical AddressesDate of BirthPassport NumbersNamesGender