Organisation that stopped e-tolls struck by cyberattack
The Organisation Undoing Tax Abuse (OUTA) has been struck by a cyberattack, according to its CEO, Wayne Duvenage, which was still affecting its advertising account with Facebook owner Meta Platforms.
OUTA is a prominent civil action and non-profit organisation based in Johannesburg that was instrumental in stopping Gauteng’s e-toll system after a decade-long legal campaign.
“A malicious cyberattack compromised OUTA’s Meta advertising account. No supporter or donor information was accessed or compromised. Your privacy remains secure,” it said.
“Despite exhausting every support channel, our advertising account remains restricted, limiting our ability to reach South Africans with campaigns that expose corruption, fight tax abuse and raise donations.”
Duvenage said that OUTA’s Meta advertising account was compromised “a few months ago.” The breach was detected early, but the organisation did suffer limited financial losses.
He explained that the Facebook platform is instrumental to the organisation, which uses it to reach millions with information that exposes corruption and holds public officials accountable.
OUTA uses Facebook to grow its supporter base, with Duvenage indicating that it was OUTA’s “most important and effective” platform.
“The breach had nothing to do with customers’ names. It was just the account that we used to promote our work on Facebook,” said Duvenage.
“We immediately followed Facebook’s required processes, investigated the matter and engaged with Meta to explain what had happened.”
He said that Meta acknowledged the incident and refunded the funds stolen from the compromised account. It was reportedly a few thousand rand.
Following the conclusion of the cyberattack, Duvenage shared that OUTA’s problems only worsened thanks to issues with Facebook’s automated support.
“Something extraordinary happened. Instead of helping us resolve the problem, Meta restricted our advertising account,” he said.
“Effectively, it has prevented us from marketing our work on Facebook, and despite repeated attempts to engage with them, we have received no meaningful explanation.”
“We have received no practical path to restore our account. In fact, we have even been blocked from opening a new advertising account by them.”
OUTA struggling with Facebook bots

Duvenage said that the cyberattack and the alleged blockage by Meta have severely impacted the organisation.
It has hampered OUTA’s ability to reach new supporters, grow public awareness and raise funding for its anti-corruption work.
The OUTA CEO called for a fair hearing before Meta and a rational explanation for why there has been no resolution to the problem.
“Here’s our appeal, if you work at Meta, or know someone who does — because we just get completely fobbed off by these bots — please can you help us deal with this issue?” Duvenage said.
Meta’s reliance on automated AI bots to fulfil complex support functions has had serious consequences in the past.
In June, several Instagram users reported that Meta’s AI support chatbot could be easily tricked into breaking into other users’ accounts.
Cybersecurity researcher ZachXBT said that all that was required to gain access to another user’s account via Instagram chatbot was the account name and an email address.
When attempting to log in to the target account, attackers could use Meta’s account recovery chatbot to send an account verification code to an email address of their choice.
The chatbot could be prompted to link a new email address and send an access code, allowing users to access others’ accounts.
Reportedly, only Instagram accounts that did not already use multi-factor authentication (MFA) could be accessed this way.
Meta soon patched the chatbot error that enabled the exploit, but not before official accounts belonging to the White House and others were affected.