Somalia has officially confirmed that its electronic visa (e-visa) platform was breached by “unidentified hackers,” putting sensitive personal data from tens of thousands of applicants at risk.
According to Somalia’s Immigration and Citizenship Agency, the breach exposed information belonging to more than 35,000 people, including names, photos, dates and places of birth, email addresses, marital status, and home addresses.
Western governments have issued security warnings. The U.S. Embassy in Mogadishu issued an alert on November 13, saying there are “credible allegations” of the hack and advising e-visa applicants to monitor their accounts carefully. The British Embassy also warned that the breach “is ongoing and could expose any personal data you enter into the system,” urging travellers to weigh the risks before applying.
In response, Somali authorities have launched an investigation to determine “the origin, extent, and impact” of the breach, and say they will publish a report and notify affected individuals directly.
The government has also quietly shut down the compromised portal (evisa.gov.so) and replaced it with a new site (etas.gov.so), but critics argue the move lacks transparency.
The breach has raised serious security concerns. Analysts warn that detailed traveller data including passport and travel plans could be used for targeted attacks, especially in a country where armed groups remain active.
