RESUME
This report discloses a significant security misconfiguration involving a publicly exposed server containing data from South African company iFacts (Pty) Ltd. The server held approximately 11.83 GB of highly sensitive personal data belonging to South African citizens, including identity documents, resumes, certificates and risk reports (around 21,000 files). Following responsible disclosure efforts, the server was eventually taken offline. However, no response or acknowledgment was received from iFacts.
About iFacts
- South Africa-based iFacts (Pty) Ltd offers comprehensive background checks, employment risk assessments, and employee evaluations to ensure integrity in recruitment. The firm provides local and international solutions, including identity verification, criminal background checks, and supplier audits, while adhering to data protection regulations such as POPIA.
Discovery of the Exposed Server
The exposed server was identified during routine security research using publicly available tools designed to locate misconfigured servers and open directories on the internet. No unauthorized access or exploitation techniques were used. Once the presence of sensitive personal data was confirmed, the scope of the investigation was limited to assessing the nature and extent of the exposure.
This server contained 11.83 GB of information on individuals evaluated by iFacts for potential employment at other companies. Upon verification, it was confirmed that it contained approximately 21,000 exposed files.
Nature of the Exposed Data
According to my investigation, this server has been exposed since 1 April 2026, which exposed the following files:
- Identity Cards
- Curriculums Vitae
- Certificates
- Diplomas
- Risk Report
- Consent Information Personal
All documents were in PDF and PNG formats.
Examples of exposed documents:
The first documents we found were named “Risk-Report”, with the main heading stating “Private & Confidential”. These documents exposed candidate data, such as names, date of birth, and gender; only the ID/passport number was redacted. In another folder, named “report/pdf”, the final reports for the candidates were located, along with the name of the client who requested iFacts services. Below is an example of the complete iFacts report.
Another document in a folder called “Documents” was titled “Consents for the Use of Personal Information (Applicants)” Some of these documents contained ID cards, diplomas, certificates, attached resumes, and personal data such as full name, ID number, contact number, alternative number, email address, physical address, postal code, population group, gender, whether the candidate had ever been convicted of an offense, and the candidate’s signature. You can see an example below.
Risks
The public exposure of this highly sensitive dataset posed severe and multi-layered risks to the affected South African citizens:
- Identity theft and impersonation: The combination of full names, partially redacted ID/passport numbers, photographs, dates of birth and residential addresses creates a complete identity package that can be used to open bank accounts, apply for credit, or commit fraud in the victim’s name.
- Document forgery: High-quality scans of identity cards, diplomas, certificates and signed consent forms can be easily altered or reused to create fraudulent credentials.
- Social engineering and phishing attacks: Detailed personal information (phone numbers, email addresses, employment history, marital status and previous addresses) enables attackers to craft highly convincing and personalised phishing or vishing campaigns.
- Blackmail or extortion: Sensitive details such as criminal records (or the absence thereof), population group and other private information could be leveraged to pressure or coerce individuals.
- Unauthorized sale of data on the dark web: Datasets containing photographs, signatures and comprehensive personal profiles have significant commercial value in underground markets.
- Compromise of personal privacy on a massive scale: The exposure of thousands of individuals private lives constitutes a serious violation of South Africa’s Protection of Personal Information Act (POPIA) and can result in long-term psychological, financial and reputational harm.
- Regulatory and reputational consequences: Beyond the affected individuals, the incident exposes iFacts and its clients to potential regulatory investigations, substantial fines under POPIA, and a significant loss of trust from both candidates and corporate clients.
Responsible Disclosure Timeline
![]() |
| Thanks to Xneelo Cloud this problem was solved; if it weren't for them, this would still be publicly available. |
- 22 June 2026: First email sent to iFacts detailing the exposure of 11.83 GB of sensitive data belonging to South African citizens. Within a few hours the server was partially blocked, but directory listing remained active.
- 23 June 2026: Follow-up email sent informing them that the files were still accessible.
- 30 June 2026: Third email sent reminding them that the problem persisted and that citizens remained at risk.
- 12 July 2026: Email sent to the web hosting provider Xneelo Cloud, requesting intervention.
- 14 July 2026: Follow-up email to Xneelo Cloud including the ticket number.
- Xneelo Cloud response: They contacted the client and requested that the information be removed from public access.
- 20 July 2026: Xneelo Cloud confirmed that the client had implemented a solution and the content was no longer visible.
No response was ever received from iFacts despite multiple attempts. Subsequent checks confirmed that the IP address and all associated routes now have improved protection.
Technical Recommendations
Immediate Actions:
- Disable public access and directory listing on all servers.
- Implement strong authentication mechanisms (multi-factor authentication, IP whitelisting, or VPN access).
- Remove or migrate all sensitive data to secure, encrypted environments.
- Replace public file access with signed URLs or temporary access tokens.
Best Practices for Sensitive Data:
- Never store personal or civil records on publicly accessible servers.
- Implement encryption at rest and in transit (AES-256 minimum).
- Apply the principle of least privilege.
- Conduct regular security audits and configuration reviews.
General Security Improvements:
- Enable comprehensive logging and real-time monitoring.
- Develop and test a formal Incident Response Plan.
- Perform periodic vulnerability assessments and penetration testing.
- Establish proper secrets management and secure configuration baselines.
Final Note
This report will be updated if additional information or responses are received from the responsible authorities.
Ethical Disclosure
This research was conducted solely for the purpose of improving security. No unnecessary data was downloaded or retained, and all findings were responsibly disclosed in accordance with standard responsible disclosure practices.
Report published: July 29, 2026
Security Researcher: chum1ng0%20Ltd.png)




0 Comments