Individuals find the right products. Businesses reach the right audience. One platform, free for both.
Vox says an Everlytic SMS service directory was publicly accessible from April to September 2026, potentially exposing customer names, not financial data.
Vox issued a POPIA Section 22 customer advisory about a data security incident linked to its Everlytic SMS services.
The company says customer names may have been exposed via a misconfigured web server directory.
Vox says financial details, passwords, ID numbers, and contact details were not affected.
Vox says a third-party provider, Everlytic, discovered on 16 September 2026 that a directory on an internal web server had been left publicly accessible without authentication.
In plain terms, this was a configuration mistake, not a break-in. It meant anyone on the internet, including automated bots that scan websites, could potentially view the contents.
Vox says Everlytic secured the directory by about 6:40pm on the same day. The directory is no longer accessible to unauthorised users.
The exposure window was estimated to run from about 9 April 2026 to 16 September 2026, around five and a half months.
According to Vox, the information that may have been exposed was limited to customer names as registered with Vox. These names appeared on an internal management report stored in the exposed directory.
Vox says the following were confirmed not affected, financial information, ID or account numbers, passwords or credentials, contact details, and special personal information.
Everlytic’s initial review of available access logs, which covered 15 days, suggested access was mainly from commercial AI and search crawlers and automated security scanners. A forensic investigation is still ongoing.
This incident highlights a common third-party risk for African businesses using outsourced messaging, email, and customer communication tools.
Even when only names are exposed, public access can increase the risk of phishing, meaning attackers can use real customer names to make scam messages look more believable.
For operators, it is also a reminder that POPIA requires disclosure when personal information may have been accessed, and vendor configuration controls and monitoring matter as much as product features.
Vox says there is no specific action customers need to take right now, but it advised users to stay alert and contact support if they have concerns.
Primary Source: Vox
Chief Content Officer (Too Long; Didn't Resign)
TL;DR Tara is Liners' AI-assisted editorial agent for African technology news, product explainers, and comparison content. Tara helps turn multiple source materials and signals into clear summaries, while Liners remains responsible for editorial standards, sourcing, and corrections.