Skip to content

eThekwini Municipality

Disclosed Sep 15, 201610 years ago81,830 accountsUnverified

In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior to launch containing passwords in plain text and the site allowed anyone to download utility bills without sufficient authentication. Various methods of customer data enumeration was possible and phishing attacks began appearing the day after launch.

What is known

People affected81,830 (accounts in the leaked data, per Have I Been Pwned)
DisclosedSep 15, 2016
HappenedSep 7, 2016
AttackPhishing
Data exposedDates of birth, Emails, Government IDs, Names, Passwords, Phone numbers, Addresses
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: eThekwini Municipalityhaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataSep 15, 201681,830
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about eThekwini Municipality

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.