Skip to main content
NOSWEAT.CO.ZA
NOSWEAT.CO.ZA

Email Exposure Risk

No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23
Website: www.nosweat.co.za
Effective Date: 10 August 2026


1. Understanding Email Exposure

Email is an essential part of how NoSweat communicates with candidates, freelancers, clients, suppliers and other business contacts.

However, email addresses can become known to third parties in a variety of ways. This may happen legitimately—for example, where a business publishes a contact email address—or unintentionally through data breaches, compromised accounts, phishing, malware, forwarding, public directories or other forms of unauthorised disclosure.

An exposed email address does not necessarily mean that an email account has been hacked.

The level of risk depends on the circumstances, including what other information has been exposed alongside the email address and whether account credentials have also been compromised.

The South African Information Regulator specifically warns individuals to be alert to phishing emails, messages and websites that request personal information or encourage users to click suspicious links. (eServices)



2. Why NoSweat Publishes Certain Email Addresses

Certain NoSweat business email addresses may be publicly displayed so that candidates, clients, regulators and other persons can contact us.

For example, NoSweat may publish contact details for:

  • general business enquiries;

  • client enquiries;

  • candidate support;

  • privacy and POPIA enquiries;

  • PAIA requests;

  • security concerns; and

  • the NoSweat Information Officer.

Publishing a business contact address inherently means that the address may be collected by automated systems, search engines, spam senders or other third parties.

For this reason, NoSweat treats public email addresses differently from passwords, banking information, identity documents and other confidential information.



3. What Are the Risks of Email Exposure?

An exposed email address may potentially be used for:

  • unsolicited email or spam;

  • phishing;

  • impersonation;

  • social-engineering attacks;

  • fake invoices or payment requests;

  • password-reset attempts;

  • credential-stuffing attempts where passwords have been reused elsewhere;

  • malicious attachments;

  • fraudulent job offers;

  • fake NoSweat communications; or

  • attempts to obtain additional personal or financial information.

The Information Regulator recognises phishing and other cyberattacks as examples of circumstances that may result in security compromises involving personal information. (Empowered Compliance Monitoring)

South African Police Service guidance similarly advises users to be cautious about email attachments and recommends against sending sensitive personal or financial information through ordinary email where safer alternatives are available. (SAPS)



4. Phishing and NoSweat Impersonation

A phishing message is designed to make the recipient believe that it comes from a legitimate organisation or person when it does not.

An attacker may attempt to impersonate NoSweat, a client, a candidate or a member of our team.

Warning signs may include:

  • unexpected requests for passwords;

  • requests for one-time PINs or authentication codes;

  • unusual payment instructions;

  • urgent requests to change banking details;

  • requests to download unexpected files;

  • links leading to unfamiliar websites;

  • slight misspellings in email domains;

  • threats intended to pressure you into acting quickly;

  • requests for unnecessary identity information; or

  • communications inconsistent with a genuine NoSweat process.

You should not assume that a communication is genuine simply because it contains information about you or appears to come from a familiar person.



5. NoSweat Will Never Need Your Password

You should never provide your NoSweat password, email password or one-time authentication code by email, WhatsApp or telephone.

NoSweat personnel should not need to know your password in order to assist you.

If someone claiming to represent NoSweat asks for your password or authentication code, do not provide it.

Please report the communication to us.



6. Protecting Your Email Account

We encourage users to take reasonable precautions to protect their email accounts.

These include:

  • using a strong and unique password;

  • not reusing the same password across unrelated services;

  • enabling multi-factor authentication where available;

  • being cautious about unexpected links and attachments;

  • checking the sender's address carefully;

  • keeping devices and software updated;

  • avoiding the transmission of unnecessary sensitive information by ordinary email;

  • reviewing unusual login notifications; and

  • changing credentials promptly if compromise is suspected.

The Information Regulator recommends measures including watching for phishing, minimising unnecessary sharing of personal information, securing devices and maintaining appropriate backups. (eServices)



7. Candidate Email Addresses

Candidates may provide NoSweat with an email address as part of:

  • registration;

  • their candidate profile;

  • a CV or résumé;

  • a job application;

  • correspondence with NoSweat; or

  • a freelance or employment engagement.

Where necessary for a legitimate application or placement process, relevant contact information may be processed or made available in accordance with NoSweat's Privacy Policy and the applicable service.

Candidates should consider whether their CV contains contact information that they are comfortable providing to prospective employers or clients.

We recommend avoiding unnecessary personal information in CVs, particularly information unrelated to professional suitability.



8. Client Email Addresses

Client representatives may provide business contact details for purposes such as:

  • creating an account;

  • posting a job;

  • communicating with candidates;

  • managing an engagement;

  • receiving invoices;

  • obtaining support; or

  • administering a NoSweat service.

These contact details will be processed for legitimate business and operational purposes in accordance with our Privacy Policy and POPIA framework.



9. Data Minimisation

NoSweat aims to collect and process only personal information reasonably appropriate to the purpose for which it is required.

Users are similarly encouraged not to send unnecessary sensitive information through email.

For example, unless specifically and lawfully requested through an appropriate process, you should avoid emailing:

  • passwords;

  • authentication codes;

  • complete banking credentials;

  • unnecessary copies of identity documents;

  • confidential medical information; or

  • other highly sensitive personal information.

POPIA requires organisations to protect the integrity and confidentiality of personal information through reasonable technical and organisational safeguards against loss, unauthorised access and unlawful processing. (Empowered Compliance Monitoring)



10. When Email Exposure Becomes a Security Compromise

Not every email exposure constitutes a reportable security compromise.

For example, an email address deliberately published by NoSweat for business contact purposes has not necessarily been unlawfully disclosed merely because it is publicly accessible.

However, circumstances such as:

  • sending personal information to the wrong recipient;

  • unauthorised access to a mailbox;

  • theft of email data;

  • malicious forwarding;

  • compromised login credentials; or

  • unlawful disclosure of confidential emails

may constitute a security compromise under POPIA.

The Information Regulator specifically gives sending an email containing personal information to an unintended recipient as an example of a security compromise. (Empowered Compliance Monitoring)



11. What NoSweat Does if Email Information Is Compromised

Where NoSweat becomes aware of a suspected compromise involving email or other personal information, we will assess and respond to the incident in accordance with our Data Breach & Security Compromise Response Plan.

Depending on the circumstances, this may include:

  • containing unauthorised access;

  • securing affected accounts;

  • changing or revoking credentials;

  • investigating relevant logs;

  • determining what information was affected;

  • working with relevant technology providers;

  • preserving evidence;

  • taking remedial security measures; and

  • making notifications required under POPIA.

The Information Regulator states that responsible parties must investigate and mitigate security compromises and that section 22 notifications are made to both the Regulator and affected data subjects where the statutory requirements are triggered. (Empowered Compliance Monitoring)

Security-compromise reports to the Information Regulator are currently submitted through its eServices system. (eServices)



12. Accidentally Sent Emails

Human error can occur.

If you receive an email from NoSweat that you reasonably believe:

  • was intended for another person;

  • contains information you should not have received; or

  • contains another person's personal information,

please do not forward, copy or use the information.

Please notify us as soon as possible at:

sebastian@nosweat.co.za

Where appropriate, we may ask you to permanently delete the message and any attachments.

The Information Regulator specifically recognises wrongly addressed emails containing personal information as a form of security compromise. (Empowered Compliance Monitoring)



13. Suspicious Emails Claiming to Be From NoSweat

If you receive a suspicious message claiming to come from NoSweat:

  1. Do not click suspicious links.

  2. Do not open unexpected attachments.

  3. Do not provide passwords or verification codes.

  4. Do not make a payment based solely on changed banking instructions received by email.

  5. Verify the request independently using contact information you already trust.

  6. Report suspicious NoSweat-related messages to us.

You may forward or report suspicious communications to:

sebastian@nosweat.co.za

Use the subject:

SUSPICIOUS EMAIL / POSSIBLE PHISHING



14. Banking and Payment Fraud

Email compromise can sometimes be used to redirect genuine payments.

If you receive unexpected instructions to change NoSweat banking details, payment details or account information, we recommend independently verifying those instructions before making payment.

Similarly, freelancers should be cautious if they receive unexpected messages claiming that payment information must urgently be changed or re-entered.

NoSweat may implement additional verification procedures before accepting material changes to payment or banking information.



15. Password Reuse

If an email address and password have been compromised on another website, attackers may attempt to use the same credentials on other services.

For this reason, users should not reuse the same password across multiple unrelated accounts.

If you believe a password associated with your NoSweat account may have been compromised elsewhere, change it promptly.

You should also change the password of any other account where the same password was used.



16. Public Data Breach Services

There are independent services that allow individuals to determine whether an email address has appeared in known data breaches.

NoSweat does not control or endorse the accuracy or completeness of third-party breach databases.

A result indicating that an email address appeared in a breach does not necessarily mean NoSweat was the source of that breach.

An email address may have been used across many websites and organisations over a number of years.



17. Our Security Responsibilities

Under section 19 of POPIA, organisations processing personal information must take reasonable technical and organisational measures to secure its integrity and confidentiality, identify foreseeable risks, establish appropriate safeguards, verify that safeguards remain effective and update them as risks change. (Empowered Compliance Monitoring)

NoSweat's security programme therefore considers risks associated with email alongside other systems through which personal information may be processed.

For security reasons, we do not publicly disclose detailed configurations, security architecture, administrative credentials or other information that could assist an attacker.



18. Your Responsibility

Information security is a shared responsibility.

Users can materially reduce email-related risk by:

  • keeping account credentials confidential;

  • using strong authentication;

  • maintaining control of their email account;

  • checking communications carefully;

  • reporting suspicious activity promptly; and

  • avoiding unnecessary sharing of sensitive information.

NoSweat cannot control the security of a user's personal email provider, device or internet connection.



19. Report an Email Security Concern

If you believe:

  • your NoSweat account has been compromised;

  • a NoSweat email account may have been compromised;

  • you received another person's personal information by mistake;

  • someone is impersonating NoSweat;

  • you received a suspicious NoSweat-related email;

  • your information has been disclosed without authorisation; or

  • another email-related privacy incident has occurred,

please contact:

Sebastian van ’t Hoff
Information Officer
No Sweat Work Media CC

Email:sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053

For urgent security matters, use the subject:

URGENT: EMAIL SECURITY CONCERN



20. Reporting Cybercrime

Serious incidents involving suspected hacking, fraud, unlawful access, extortion or other criminal conduct may also be reported to appropriate law-enforcement authorities.

South Africa's Cybercrimes Act 19 of 2020 establishes offences and investigative mechanisms relating to cybercrime. (Government of South Africa)

NoSweat may cooperate with appropriate authorities where necessary and legally permitted.



21. Your POPIA Rights

Subject to applicable law, you may have rights to:

  • request access to personal information NoSweat holds about you;

  • request correction of inaccurate information;

  • request deletion where legally appropriate;

  • object to certain processing;

  • withdraw consent where consent is relied upon;

  • complain about improper processing; and

  • lodge a complaint with the Information Regulator.

The Information Regulator provides prescribed forms for objections, correction/deletion requests and privacy complaints. (Empowered Compliance Monitoring)



22. Related NoSweat Policies

This page should be read together with our:

Privacy Policy
POPIA & Data Protection
Cookie Policy
PAIA Manual
Information Officer Registration & Contact Details
Record of Processing Activities (ROPA)
Data Breach & Security Compromise Response Plan
Direct Marketing Policy
Do Not Sell or Share My Personal Information



23. Changes to This Page

NoSweat may update this page as technology, security threats, our services or applicable legal requirements change.

The latest version will be published on www.nosweat.co.za.



24. Contact NoSweat

For email security, privacy or personal-information concerns:

No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23

Information Officer: Sebastian van ’t Hoff
Email:sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053
Website:www.nosweat.co.za
South Africa

For suspected phishing or email-security incidents, please use:

SUSPICIOUS EMAIL / POSSIBLE PHISHING

or, where personal information may have been compromised:

URGENT: POSSIBLE DATA BREACH

http://www.nosweat.co.za/email-exposure-risk