Whenever I see a serious cybersecurity lapse, I believe it must be called out. Cybersecurity is not a luxury, particularly when we are talking about a sovereign state, diplomatic missions and official government communications.
A document issued by the Embassy of the Republic of Zimbabwe in London, dated 28 September 2026, provides a typical example. The embassy’s own notice for its consular outreach programme lists [email protected] as one of its official contact addresses. The embassy’s current website also publicly lists both [email protected] and [email protected], alongside its government address, [email protected]
By Jacob Mtisi
Why is a sovereign state using a free Yahoo Mail account for official diplomatic and consular communication?
I am not suggesting that the mere use of Yahoo proves that a foreign government is reading Zimbabwe’s emails. That would be an allegation requiring evidence. But it is precisely the kind of unnecessary third-party dependency that a government dealing with sensitive diplomatic, consular and potentially national-security information should be examining.
Yahoo’s own privacy documentation says that Yahoo systems may analyse and store communications content, including incoming and outgoing email. Yahoo also states that information can be transferred, processed and stored in countries other than the user’s own, including the United States and that it may be required to disclose personal data in response to lawful requests from public authorities.
That should make every Zimbabwean cybersecurity professional sit up and take notice.
The issue is not whether Yahoo is a reputable company. It is whether the Government of Zimbabwe should be placing official diplomatic correspondence on a consumer email platform when it has the ability to operate controlled government email infrastructure.
There is an even greater irony here. Zimbabwe frequently speaks about sovereignty, national security and the strategic threat posed by foreign powers. Yet cybersecurity sovereignty is not achieved by making speeches. It is achieved by controlling your infrastructure, your identities, your communications and your data.
A government embassy should have properly managed government email addresses, strong authentication, encryption where appropriate, centralised security monitoring, retention policies, access controls, audit trails and clearly defined data-residency and incident-response arrangements.
Diplomatic communication should not depend on a free email address. And this is not simply an issue for the Ministry of Foreign Affairs. The Ministry responsible for ICT and the country’s cybersecurity authorities should be asking how many other government departments, diplomatic missions, parastatals and public institutions are conducting official business through Gmail, Yahoo, Outlook.com or other uncontrolled consumer accounts.
If the answer is significant, then Zimbabwe has a much bigger cybersecurity governance problem than one embassy email address.
government communications should be brought under a properly secured national government email and communications architecture.
We cannot demand digital sovereignty while outsourcing parts of our official communications infrastructure to consumer platforms.
Zimbabwe is a sovereign state. Its official communications should look and operate like the communications of a sovereign state.
This is precisely why cybersecurity professionals must sometimes be uncomfortable. If we see the vulnerability, we must say so before someone exploits it.
The Embassy’s current website confirms the Yahoo addresses cited above and also lists its government email address, so the issue can and should be addressed transparently by the relevant authorities.
Engineer Jacob Kudzayi Mutisi
+263772278161











Comments