Profit.kz · August 5, 2026 · 1Cifer
A Kazakhstani logged into someone else's eGov account and showed it on social media: a lesson in the cost of simple flaws
A telling story unfolded in Kazakhstan: a user discovered he could log into someone else's eGov account and, instead of quietly contacting support, demonstrated it on social media. The video spread, agencies had to respond publicly, and trust in digital government services was back on the agenda.
There are two lessons here, and neither is about eGov. First: vulnerabilities are more often found by ordinary users — by accident or curiosity — than by attackers. Second: if a person has no simple, visible way to report a problem directly, they will report it to everyone at once. A public reckoning always costs more than a quiet fix — both reputationally and operationally.
For a company in Kazakhstan with a website, an app or a customer portal, the takeaway is concrete: set up a channel for security reports — at minimum a dedicated email address in a visible place — and agree internally on who responds to such messages and how fast. Larger companies can go further and announce a bug bounty. Paying a finder quietly is cheaper than reading about your hole in someone else's social feed.


