Notice of Data Security Incident
Affecting Everlytic SMS Services
We are issuing this notice in accordance with our obligations under the Protection of Personal Information Act 4 of 2013 (POPIA) to keep you informed about an incident that may have affected your information.
Who this notice affects: Current and former Vox customers who subscribed to an Everlytic SMS communication service through Vox.
What happened
Vox uses Everlytic as a third-party provider to deliver SMS and email communication services to our customers. On 16 September 2026, Everlytic discovered that a directory on their internal web server had been left publicly accessible without authentication due to an incorrect configuration setting. This was not the result of a hack or forced entry — the directory was inadvertently exposed in a way that allowed it to be found and accessed by anyone on the internet, including automated web crawlers.
Everlytic acted immediately upon discovery and fully secured the directory by approximately 6:40pm on 16 September 2026. The directory is no longer accessible to unauthorised persons.
Information that may have been affected
| What was exposed | Your customer name as registered with Vox, as it appeared on an internal management report held within the exposed directory. |
|---|---|
| Estimated period of exposure | From approximately 9 April 2026 to 16 September 2026 (approximately five and a half months). |
| Who accessed it | Based on 15 days of available access logs, accesses were attributable to commercial AI and search crawlers (Amazon, OpenAI, Apple, Exa), automated security scanners, and what appears to be internal Everlytic activity. Everlytic’s forensic investigation is ongoing. |
- Financial information
- ID or account numbers
- Passwords or credentials
- Contact details
- Special personal information
Steps taken
Everlytic has removed public access to the directory, restored correct access controls, preserved relevant system and access logs, and engaged independent security specialists to conduct a full forensic investigation. They are also reviewing and strengthening their directory configuration and change-management controls to prevent recurrence.
Vox is actively monitoring the investigation and evaluating the full scope of the incident as information becomes available from Everlytic. We will notify any further affected customers promptly if additional personal information is found to have been involved.
What you should do
Given that only your customer name may have been exposed, and no financial, credential, or sensitive personal information was contained in the affected directory, there is no specific action you are required to take at this time. We encourage you to remain vigilant and to contact us if you have any concerns.