Image created by AI
The Companies and Intellectual Property Commission (CIPC) in South Africa has come under scrutiny following a security breach that placed clients’ and employees’ personal information at serious risk. In a grave admission, the CIPC acknowledged that a breach had taken place with individuals' personal details being unlawfully accessed.
However, this story intensifies as the hackers, a ransomware group claiming responsibility, allege that they have had unauthorized access to the CIPC's system since 2021 - substantially longer than the commission has admitted. Moreover, the group accuses the CIPC of deceptive conduct, attempting to conceal the full extent of the breach and its failure to remedy known security vulnerabilities.
The hackers elaborated that they exploited a weak spot in the system developed by Sword South Africa, which purportedly allowed them unrestricted access to the CIPC’s database. This unrestricted access included sensitive information such as plain text passwords and credit card details. They could manipulate company records, including amending director details and more.
This revelation not only challenges the CIPC's claim that the issue was swiftly dealt with but also suggests that the CIPC may have neglected to perform critical security audits and improvements - behavior particularly egregious in light of the POPIA requiring stringent data protection measures.
The ransomware group disclosed that their most recent incursion into the CIPC's network unveiled the same exploit still open – indicating that no significant security enhancements had been made. This occasion also saw the hackers accessing back-end source code from Sword South Africa, which they claim to be fraught with "ridiculous security holes."
The attackers argue that the commission acted to publicly acknowledge the breach under duress, solely prompted by the hackers’ threat to go public. If true, this would indicate a reactive rather than proactive stance on the CIPC's part concerning data security.
Further complicating the matter is the CIPC's reticence to discuss the allegations, deeming the questions related to the breach as too sensitive. Instead, Lungile Dukwana, CIPC chief strategy executive, stated that the commission is working in conjunction with law enforcement and that the initial media release is sufficient for the current stage of their investigation.
This incident showcases a worrying state of cybersecurity in essential government databases in South Africa. It emphasizes the need for a more transparent and assertive approach to cyberspace threats, adequate compliance with personal information protection laws, and an overall reassessment of data protection protocols amongst state-run entities.
Sword South Africa, the software development house implicated in the revelations, has not issued a response, adding another layer of concern regarding accountability and security assurance within the software and technology industry.
With no further transparency provided or reassurance from the implicated parties, the South African public remains anxious about the handling of their personal information and the systemic changes needed to prevent future security breaches of this magnitude.