US Become 1st Nation Alerts Somalia’s Electronic Visa (E-Visa) Data Breach

0
134

The United States has become the first nation to issue a formal security alert regarding a major data breach in Somalia’s electronic visa (e-visa) system, warning that the personal information of approximately 35,000 applicants—including thousands of U.S. citizens—may have been exposed to hackers.

The U.S. Embassy in Somalia released the advisory on November 11, 2025, citing credible allegations that unidentified hackers accessed the Somali e-visa portal. Leaked data reportedly includes applicants’ full names, passport photos, dates and places of birth, email addresses, marital status, and home addresses.

The breach was first exposed days earlier by the Horn Tribune, which published a detailed investigation on November 7, 2025, revealing that the e-visa system suffered from a critical security flaw: application files were openly accessible online by simply changing sequential numbers in the website URL. No login or authentication was required, allowing anyone with basic technical knowledge to view and download sensitive visa records.

According to the Horn Tribune report, the vulnerability was active for weeks before being discovered by a Somali-American cybersecurity researcher in late October. The publication obtained and verified samples of leaked data, confirming that thousands of applications—including those from diplomats, journalists, aid workers, and UN personnel—were exposed.

The outlet also reported that the Somali Immigration and Citizenship Agency (ICA) took the original site (evisa.gov.so) offline on November 10 and migrated to a new platform (etas.gov.so), but failed to notify applicants or conduct a public breach disclosure.

The U.S. Embassy stated it cannot confirm whether specific individuals were affected but urged all e-visa applicants to assume their data may have been compromised. The advisory emphasized heightened risks in Somalia, a country under a Level 4 “Do Not Travel” warning due to terrorism, kidnapping, and civil unrest.

https://so.usembassy.gov/alert-federal-republic-of-somalia-fgs-electronic-visa-e-visa-data-breach/