Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Adama City Government Exposes 29 GB of Sensitive Ethiopian Citizens' Data

The Adama City government in Ethiopia exposed a 29 GB database containing sensitive personal information of its citizens, including full names, phone numbers, ID numbers, and financial records. The data breach, discovered by security researchers, involved an unsecured database accessible without authentication, potentially putting thousands of residents at risk of identity theft and fraud.

Background

- Adama is one of Ethiopia's largest cities (located in the Oromia region, about 100 km southeast of Addis Ababa), and this breach involves its municipal government's data infrastructure. - The exposed 29 GB trove reportedly contained highly sensitive personal information on Ethiopian citizens: national ID numbers, passport data, biometric records, health information, financial details, and internal government documents. - The data was left accessible without a password on a publicly exposed server (likely an unsecured cloud storage bucket or database — a common misconfiguration known to security researchers). - This is part of a broader pattern: municipal and state governments across Africa have rapidly digitized services but often lack the cybersecurity resources or expertise to secure the resulting data, leading to repeated large-scale leaks. - For Ethiopian citizens, the breach is particularly concerning because the country's national ID system (ID-nya or Kebele ID) is used for everything from voting to banking, making leaked data nearly impossible to replace or revoke.