DEEP DIVE DATA
×
DATA RIGHTS & BREACH LAW · JUNE 3, 2026

EcoCash's X account was hacked for 7 hours.Here's what the law says should happen next.

7h 12m
ACCOUNT EXPOSED
5
PII FIELDS VISIBLE
24h
POTRAZ DEADLINE
SWIPE TO READ  ›
WHAT HAPPENED

On June 3, 2026, EcoCash's X (Twitter) account was hijacked from 1:42 PM to 8:54 PM — over seven hours.

An individual claiming EcoCash had stolen $35 from them took control and posted explicit content. Critically, whoever was behind the hack had full access to EcoCash's customer support DMs for the entire window. This was not a public leak — but unauthorised access to private customer conversations is a notifiable data breach regardless.

What the attacker could read in customer DMs: full name, phone number, national ID details, account number, and transaction references — together, Personally Identifiable Information (PII) under Zimbabwean law.
THE INCIDENT TIMELINE

June 3, 2026

1:42 PMFirst public signal (@VWGroupFan, 24.3K views)
DuringAttacker posts explicit content, reads support DMs
7h 12mTotal window of exposure
8:54 PMEcoCash regains control (per Techzim)

No public statement was issued by EcoCash or Econet Zimbabwe during the entire seven-hour window.

UPDATE · JUNE 10, 2026 · 5:41 PM CAT

EcoCash says data wasn't compromised

On June 10, Techzim published a video in which EcoCash responded to direct questions about the incident. The company stated its internal systems were not affected and that customer DMs were not compromised. No offensive material remains on the account.

No direct communication to affected customers has been confirmed at the time of writing. If you have not yet contacted EcoCash directly, that is the right first step.

THE UNADDRESSED GAP
30 hrs
Possible real exposure window — not the 7 hours publicly reported

EcoCash's statement does not address when the compromise actually began. The earliest point we can publicly trace is June 3, when the breach was first documented — but the last legitimate activity visible on the account dates to June 2, with nothing traceable between that point and the June 3 documentation.

If the account was already under unauthorised control from June 2, the access window runs to roughly 30 hours, not seven. EcoCash has not commented on the June 2 gap.

THE LEGAL CLOCK

What should have happened — and when

The moment this breach was discovered, Zimbabwe's Cyber and Data Protection Act and its 2024 Regulations began counting. EcoCash, as a licensed mobile money operator handling customer financial data, is a "data controller" — legally bound to a specific response schedule. This is not discretionary.

Financial data combined with national ID details almost certainly meets the threshold of "high risk to the rights and freedoms" of affected individuals — triggering the most stringent notification obligations.

FOUR DEADLINES, ONE BREACH CLOCK
24 hoursNotify POTRAZ — submit Form DP3
72 hoursNotify affected customers directly
14 daysRespond to POTRAZ information requests
21 daysConclude investigation, submit final report

The 24-hour POTRAZ deadline fell at 1:42 PM on June 4. The 72-hour direct-notification deadline fell at 1:42 PM on June 6. A vague tweet does not satisfy the direct-notification requirement — each data subject must be contacted personally.

LIVE COMPLIANCE TRACKER

Where are we on the legal clock?

Breach detected 1:42 PM CAT, June 3, 2026. All deadlines run from that moment (UTC+2). Cards turn amber near a deadline, red once it has passed without confirmed action.

Progress through 21-day investigation window
Jun 324h72h14dJun 24
ACCOUNTABILITY

Four questions the company must answer

  • 01 · Were the right safeguards in place? The law requires "appropriate technical and organisational measures" to protect customer data. Jun 10 via Techzim: not answered — EcoCash said internal systems weren't affected but didn't describe what controls protected the X account.
  • 02 · Did they have a Data Protection Officer? Required by law for companies of this scale and data sensitivity. Jun 10 via Techzim: not addressed at all.
  • 03 · What was the legal arrangement with Twitter? The law requires a formal contract with any third party processing data, including binding security obligations. "It happened on Twitter" is no defence. Jun 10 via Techzim: not addressed.
  • 04 · Who bears accountability? The company is legally responsible for its representatives, agents, and processors — accountability cannot be delegated away. Jun 10 via Techzim: not addressed — no one named, no remediation described.
YOUR RIGHTS

What you — and the public — can demand

Breaches of financial PII undermine trust in the entire mobile money ecosystem. The law gives you specific tools, not just sympathies.

  • Right to be informed — direct notification if the breach poses high risk, not a general statement.
  • Right to lodge a complaint — a formal POTRAZ complaint triggers a structured regulatory response.
  • Right to request an inquiry — POTRAZ can investigate at your request, independent of the company.
  • Right to inspect the register — verify whether the company was even authorised to process your data this way.
ACTION GUIDE

What you should do right now

Contacted officially?Not past 72h = a violation to report
Filed with POTRAZ?Formal complaints trigger investigations
You contacted them, or vice versa?Shapes scope of exposure & standing
  • File a formal complaint with POTRAZ — include the data exposed, the time window, and whether you were notified.
  • Request a copy of EcoCash's breach report (Form DP3) — if none exists, that absence is evidence of non-compliance.
  • Inspect the public register of licensed data controllers to verify EcoCash's authorisation.
  • Monitor your mobile money wallet for unusual activity and report suspicious contact immediately.
CONSEQUENCES

What happens if they failed to comply

Financial penaltyFines up to Level 11
Criminal liabilityImprisonment for responsible officers
Regulatory actionPOTRAZ inquiry & formal investigation
Licence reviewData-processing authorisation may be revoked
"It happened on Twitter" is not a legal defence if the company did not have adequate controls, contracts, and a designated officer in place before the breach occurred.
THE BOTTOM LINE

The clock doesn't pause because a company stays quiet

Seven hours, possibly thirty. Five categories of PII. A statement, nine days later, that answers what wasn't taken but not when the taking actually started.

The law does not require you to trust the company's timeline. It gives you the standing to demand a better one.

Whether EcoCash met its 24-hour, 72-hour, 14-day, and 21-day obligations is answerable — through a POTRAZ complaint, a formal request, or an inspection of the public register. You don't need to wait for the company to volunteer it.

END OF STORY

Deep Dive Data covers Zimbabwe data rights and mobile money regulation.

Sources: @VWGroupFan on X — first public signal of the hack, 1:42 PM Jun 3, 2026 · @RoboXnet on X — further documentation of the compromised account · ZimLive — EcoCash X account hacked by individual claiming company stole $35 · Techzim — EcoCash regains control of X account, 8:54 PM Jun 3, 2026 · Zimbabwe Cyber and Data Protection Act (Chapter 12:07) · Cyber and Data Protection (General) Regulations, 2024 (S.I. 163 of 2024), breach notification obligations per Part IV · Techzim — how POTRAZ can help if you're dissatisfied with your service provider's handling of your complaint · Techzim on X — EcoCash responds: internal systems not affected, DMs not compromised, Jun 10, 2026 · 5:51 PM CAT.