Recent Data Leaks
Live
← Back to timeline

eThekwini Municipality

Have I Been PwnedConfirmed breachAdded September 15, 2016Occurred September 7, 201681,830 accountseservices.durban.gov.zaAll eThekwini Municipality breaches →
What was exposed
Dates of birthDeceased dateEmail addressesGendersGovernment issued IDsNamesPassport numbersPasswordsPhone numbersPhysical addressesUtility bills
What to do if you were affected
Details
In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior to launch containing passwords in plain text and the site allowed anyone to download utility bills without sufficient authentication. Various methods of customer data enumeration was possible and phishing attacks began appearing the day after launch.
Frequently asked questions

What is the eThekwini Municipality data breach?

In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior...

When did the data breach happen?

This data breach occurred around September 2016.

How many accounts were affected?

Around 81,830 accounts were affected.

What information was exposed?

Exposed data included Dates of birth, Deceased date, Email addresses, Genders, Government issued IDs, Names, Passport numbers and Passwords.

What should I do if I was affected?

Change your password for this account, and anywhere you reused it. Turn on two-factor authentication. Place a fraud alert or credit freeze with the major credit bureaus to block new accounts opened in your name. Expect more phishing and spam at this address. Treat messages that reference this company with extra caution. Watch for text-message phishing and SIM-swap attempts on your phone number. Be wary of targeted scams that use your personal details to sound convincing.

View on source ↗
Related breaches