Popular software used by South African companies targeted by hackers
South African tech companies adopting popular, publicly available AI software for critical business operations may be exposing internal data to attackers, Check Point Software has warned.
Threat actors employ their own large language models to identify the processes and systems these companies worked on, likely believing them to be private, and exploit them as attack vectors.
Ian van Rensburg, security engineering head for Africa at cybersecurity firm Check Point Software, told MyBroadband that threat actors use AI to find the information tech companies feed into these models.
“The fact is that if you take personal data, company data and slap it into ChatGPT and then want answers, that data is going into the public domain,” he said.
“If you write code, that code is also going into the public domain.”
Hackers use AI engines to scour the web for applications built with public AI tools like Anthropic’s Claude or Google’s Gemini.
Van Rensburg explained that these engines identify and reveal the code used to build these platforms and applications, potentially providing a backdoor into company systems.
“All of a sudden, there is an external-facing application, and hackers understand that code because their AI picked it up.”
The emergence of advanced AI models like Anthropic’s Mythos raised serious concerns in the information security sector, with reports that it could serve as a “mega hacking” assistant.
Anthropic said that, if prompted, Mythos could rapidly research and expose zero-day vulnerabilities across major operating systems and web browsers.
For that reason, Anthropic said it would limit access to Mythos, offering it to companies to help close security vulnerabilities before attackers gained access to similarly advanced AI tools.
However, on 21 April, Bloomberg reported that “unauthorised users” had gained access to Mythos. While their interests appeared benign, it raised questions about Anthropic’s security hygiene.
AI arms race between hackers and security companies

Van Rensburg said that the emergence of generative AI and its ease of use have changed cybersecurity worldwide. Now, both threat actors and cybersecurity companies are embroiled in an AI arms race.
“Hackers are using AI, and their attacks are now at the speed of a machine and not a human. These things get exploited very quickly,” he said.
AI is used by hackers to monitor the dark web for newly identified vulnerabilities and exploits. They also use large language models to write malicious code and create new exploits.
They also use AI to fuel social engineering attacks, such as creating deepfakes and highly convincing phishing campaigns that could fool even seasoned and tech-savvy users.
“AI can write phishing emails, create false websites, and so forth because AI is so good at mimicking that it implements the correct website look, the logos, the feel.”
Van Rensburg gave the example of phishing emails that were made to look like official delivery courier messaging.
Discovery’s SpendTrend26 South African Consumer Survey recently revealed that courier and delivery scams were now the most prevalent form of fraud in the country.
It said that 46% of respondents in the survey reported being targeted by courier and delivery scams, topping 41% that said they were targeted by email and SMS scams.
South Africa’s e-commerce explosion has led to increased use of courier services, which threat actors have exploited using AI to craft targeted fraud attempts.
Van Rensburg said that these scams have created a new cybersecurity priority for companies in South Africa, as threat actors look to gain access to systems by stealing user identities.
This created another shift in cybersecurity in the country, as protection moves from traditional perimeter-based firewalls to zero-trust user identity protection.
Identity is the new perimeter

“These days, you cannot just put in a firewall and think that you are safe and secure,” he said.
“You cannot just protect the perimeter… You need to protect identity, you need to protect way beyond the perimeter.”
Identity theft is a method threat actors use to bypass most of the cybersecurity protections South African companies use today, enabling them to deploy ransomware and data theft techniques.
Van Rensburg said companies in South Africa should prioritise limiting access to their systems as a cybersecurity measure. “Identity is the new perimeter,” he said.
He said systems needed to be completely untrusting and run several tests to ensure that the user who logs in is exactly who they claim to be.
“When I log in from a device, it actually sees who I am. It identifies me. It looks at my security posture. It looks through certificates and so forth that I am who I say I am before I actually connect,” he said.
“That is what’s important these days.”