South African government leaving doors wide open to cybercriminals
Hundreds of South African government websites are wide open to cyberattacks thanks to years of poor maintenance and disregard, a cybersecurity researcher has claimed.
Despite this, the State Information Technology Agency (SITA), which is responsible for a large portion of the government’s ICT infrastructure, previously said that its systems were secure.
According to a Ground Up report, cybersecurity researcher Joel Cedras found hundreds of exploitable vulnerabilities across thousands of government websites hosted by SITA.
Cedras was part of the team of young researchers that uncovered massive fraud in South Africa’s Social Relief of Distress (SRD) grant system in 2024.
They launched an investigation that revealed the fraud was enabled by a chain of security flaws across several entities in South Africa, including cellular service providers and banks.
In the latest report, Cedras said that of the 1,100 public-facing systems in SITA’s network, 1 in 7 carry a known security vulnerability that has not yet been patched.
This problem is even more severe in non-SITA government networks, where 516 public-facing systems were allegedly found to be riddled with exploitable vulnerabilities.
The network is nearly half the size of the SITA network, yet has nearly as many critical security flaws, with one in five carrying a known vulnerability, he said.
“Our security operations teams operate on a continuous, 24/7 basis and are equipped with monitoring and threat-detection capabilities.”
Tlali Tlali, head of corporate affairs at SITA, previously told MyBroadband that its security operations teams monitor the network 24/7 and are equipped to handle threats as they arise.
In new feedback, Tlali told MyBroadband that there are ongoing modernisation initiatives aimed at improving the security posture and performance of critical government systems.
“Many departments host their systems in their own environments or through approved third-party service providers, while still utilising SITA’s network services for connectivity and secure access.”
“SITA remains committed to the continual improvement of the Government Private Network (GPN) security posture through the implementation of enhanced security controls,” he said.
Tlali said that SITA is also implementing proactive monitoring and ongoing cybersecurity improvement initiatives to enhance security across the network.
Risks of cyberattacks and ransomware on state institutions

Cedras told MyBroadband that the risk of a SITA-hosted network being struck by a cyberattack was extremely high.
“I would ask whether it has happened already. Six of the vulnerabilities found were on the Known Exploited Vulnerabilities list,” he said.
“Both on and off SITA’s network, some government servers have been unpatched for over a decade. The doors are open.”
He said there are many SITA networks he considers highly vulnerable and susceptible to cyberattacks due to unpatched vulnerabilities.
Some examples were the Deeds Office, which he discovered had over 450 vulnerabilities. Meanwhile, the Eastern Cape Health Department was found to be vulnerable to a type of attack called ProxyLogon.
This attack allows attackers to impersonate an admin and get access to their Exchange server and its email, Cedras explained. This could lead to a major data breach or double-extortion attack.
Other websites ripe for exploitation included those of the Department of Sports, Arts and Culture, which had more than 100 vulnerabilities on a single server.
The Limpopo Government had more than 150 vulnerabilities on a single server hosting its infrastructure, while the Department of Home Affairs had over 100 open vulnerabilities.
“The list goes on. And that’s just on SITA’s network!” he said. “There have already been several exploits. More will happen unless the situation is addressed.”
Statistics South Africa was struck by a ransomware attack in May by a group of threat actors called XP95, which vanished from the scene almost as quickly as it emerged.
The group claimed to have successfully breached the agency and said it stole 154 GB of data from an unspecified Stats SA server.
XP95 demanded R1.7 million to prevent the leaking of the data it allegedly collected from the server and set a deadline for later that month. Stats SA said that it would not pay.
Cedras said the risk was that these servers hold data that South African citizens have provided to the government, including identity documents, title deeds, criminal histories, and more.
“There is a serious risk of leaking of sensitive data, which can facilitate fraud and other crimes against citizens,” he explained.
“Many of the systems on the network are demonstrably under-maintained and extremely out of date. A ransomware attack could also shut down multiple government services at once.”
A network-wide ransomware attack through one of SITA’s or the wider government’s unsecured networks would render South Africans unable to use government services.
Tlali said that SITA recently conducted a security assessment across National and Provincial government departments in conjunction with key government stakeholders.
“These assessments highlight areas that require remediation to improve security posture, which government departments need to prioritise and work with SITA to address,” he said.