Security4.05.2026

Obvious security flaw in website of important R54-billion South African fund

The official website for the National Student Financial Aid Scheme (NSFAS) no longer has a valid Transport Layer Security (TLS) certificate, hindering students from accessing the site.

According to the security details on the website, nsfas.org.za, it expired on Friday, 1 May 2026. Without a valid TLS certificate, communication between users and the web server is unencrypted.

NSFAS is one of the largest payment facilitators in South Africa, processing monthly payments for over a million beneficiaries. It has a budget of R54 billion for the 2026/2027 financial year.

The inability to renew its TLS certificate, a routine security process, points to a larger, systemic problem with the agency’s cybersecurity protocols.

TLS certificates provide digital validation and encryption of a website’s online identity. They are used to secure connections between user browsers and an organisation’s webpages.

When certificates expire, connections between browsers and websites are no longer secure, and any sensitive data transmitted may be at risk of interception from threat actors.

That means data such as login credentials, payment information, or personal details may be exposed and stolen, according to certificate vendor Sectigo.

“Modern web browsers will display warning messages to users attempting to access a site with an expired security certificate,” the company explained.

“This can erode users’ trust and deter visitors from continuing to the site, potentially leading to a loss of traffic and credibility.”

When tested on Monday morning, Google Chrome prevented users from accessing the main NSFAS website. The site was flagged as “untrusted.”

The my.nsfas.org.za portal appeared to have a valid certificate and remained accessible. This indicated that beneficiaries could still access their accounts without the threat of interception.

However, any support resources, including student loans, student accommodation, important forms, information on the appeal process and more, are difficult to access due to the expired certificate.

Users could still access the site by bypassing their browser’s security block via the “advanced options” available on the warning page, but they would do so at their own risk.

Dr Karen Stander, former chair of the scheme’s board of directors, said in August 2025 that NSFAS’s ICT systems were constantly at risk due to poor security procedures.

“The organisation’s ICT systems are misaligned with business requirements and lack integration,” she said during a media briefing.

She said that the scheme’s lacking ICT systems exposed troves of private information from students to “severe cybersecurity risks.”

In 2024, the Portfolio Committee on Higher Education recommended that NSFAS strengthen its ICT systems as a matter of urgency “to curb student data falling into the wrong hands.”

Tebogo Letsie, chairperson of the committee, said the department must conduct a forensic investigation into the National Treasury funds allocated to the scheme to improve its ICT systems.

MyBroadband contacted NSFAS upon discovering the expired TLS certificate, but did not receive a response by publication.

Student discovered security vulnerability at NSFAS

Jordan Bettridge (left) and Connor Bettridge (right).

In 2025, a Varsity College student discovered a vulnerability in the scheme’s ICT systems that, if exploited, would allow attackers to access highly sensitive services.

The vulnerability could allow attackers to take over an administrative user account with which they could approve or reject funding applications and access sensitive financial information.

The student, Connor Bettridge, first discovered the vulnerability after he noticed that a panel on the scheme’s web portal displayed every message sent by the system to every user.

This included one-time PINs (OTPs) that were generated and sent to people who had forgotten their passwords.

Bettridge continued digging after discovering this flaw and found that the website’s API was extremely poorly secured.

Bettridge then brought in his older brother, Jordan, to help him investigate for further vulnerabilities. The pair discovered the extent to which an attacker could exploit the NSFAS API.

They revealed how a threat actor could exploit the API to rapidly download private information from the millions of students who used the system in the past three years.

A more critical vulnerability discovered by the pair showed how an attacker could use the API to gain administrative access to the NSFAS webpage.

“NSFAS became aware of a potential security weakness and immediately activated its information security and incident management protocols,” said NSFAS after the vulnerability was reported.

“The matter was prioritised, investigated, and appropriate remedial actions were implemented without delay.”


NSFAS website blocking access to students


Pictured in article thumbnail: Waseem Carrim, Acting Chief Executive Officer of NSFAS.

Show comments

Latest news

More news

Trending news

Poll

Which video streaming service do you think offers the best value for money?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter