Eskom insiders exploited prepaid electricity system
Several Eskom employees have been implicated in a scheme to create billions of rands of fraudulent prepaid electricity vouchers, enriching themselves while the utility received no income for the units.
Syndicates operating inside Eskom sold large volumes of electricity on the black market for as little as 25 cents per unit.
Based on advertisements placed on social media platforms, “ghost vendors” offered 600kWh electricity vouchers for around R150, which translates to a unit price of R0.25/kWh.
The state-owned power utility revealed in its annual report, published in September, that it was investigating options to prevent the use of these fraudulently generated 600kWh electricity vouchers.
The average per-unit price Eskom charged to residential customers in 2023 and 2024 was around R3/kWh — twelve times more than what the electricity thieves were charging.
Larger vouchers were also available, offering even cheaper per-unit prices. However, the 600kWh tokens appeared to be the most popular, which is likely why Eskom highlighted them in its report.
The scale of the fraud is likely to have impacted Eskom’s financial health, exacerbating its debt problem and resulting in higher tariff increases to compensate for the lost revenue.
In its latest annual report, Eskom revealed that total losses due to criminal conduct during its 2024/25 financial year were R7.2 billion, up from R6.7 billion the year before.
Most of this — R7.1 billion in 2025 and R6.4 billion in 2024 — is related to estimated non-technical energy losses arising from electricity theft.
However, MyBroadband understands that the actual losses are much larger than Eskom’s estimates. Prepaid ghost vending may also have contributed to load-shedding.
Eskom first disclosed that its online vending system (OVS) for prepaid electricity was breached in its previous integrated report, published in December 2024.
Eskom introduced the OVS in 2008 to combat ghost vending using old offline credit dispensing units (CDUs).
Corrupt Eskom officials assisted syndicates in obtaining the equipment, technical expertise, and system access needed to generate fake electricity tokens — first on CDUs and later on the OVS.
University of Johannesburg research associate and forensic investigator Calvin Rafadi has explained that Eskom tried to recall its CDU machines when it launched the online vending system.
However, Eskom officials stole several of the machines from where they were kept in storage. They also obtained the disks and other equipment necessary to alter the electricity prices on the devices.
The CDU-based “ghost vending” problem persisted long after the online vending system was launched, with law enforcement struggling to dismantle the criminal syndicate behind the theft.
Prepaid electricity meter security questions

MyBroadband also understands that the fraudulent tokens generated by Eskom’s compromised system could have been used on meters linked to municipal distribution networks.
However, Eskom said that this was not technically possible, as meters configured for use in a municipal supply area could not accept Eskom Direct electricity tokens.
The City of Tshwane metropolitan municipality also dismissed concerns, suggesting that its system prevents ghost vending from taking place.
“The City of Tshwane operates on a real-time vending platform; therefore, there are no reported ghost-vendors in the city’s vending system,” a spokesperson told MyBroadband.
Following Eskom and Tshwane’s feedback, MyBroadband spoke to representatives of Landis+Gyr, a prominent electricity meter manufacturer.
While the company initially stated that it could not answer questions about Eskom ghost vending, as it does not supply the OVS, it was willing to address technical questions about its meters.
MyBroadband asked whether it was possible to reconfigure a municipality’s prepaid meters to accept Eskom Direct tokens, and vice versa
“Landis+Gyr manufactures and supplies meters in accordance with customer-approved specifications and requirements,” it said.
“In some cases, customers may opt to have their meters configured with a manufacturer’s default Supply Group Code (SGC).”
Landis+Gyr explained that this configuration allows the utility or municipality to perform a key change from the manufacturer’s default SGC to their own unique SGC.
“Only once the key change is performed will the meter then accept prepayment credit tokens from the utility vending system,” it said.
“While the meter contains the manufacturer’s default SGC, it cannot accept prepayment credit tokens until the utility-specific key change is performed.”
Eskom reports improvements

Eskom previously reported that it had reduced fraud linked to its OVS to very low levels by improving physical security, cyber resilience, and operational controls.
One of its key future interventions is accelerating the development of a new, secure vending system to replace the OVS.
“Expanded investigative measures, conducted in collaboration with law enforcement, have been concluded for some of the implicated employees, with the internal process resulting in their dismissal,” it added.
“Certain elements are to be referred to authorities, and the company will cooperate fully.”
MyBroadband asked Eskom during its results presentation last year what the value was of the fraudulent 600kWh vouchers generated from its OVS.
Eskom Group CEO Dan Marokane did not answer the question. Instead, he provided additional detail about the power utility’s approach to ghost vending.
Marokane explained that they were using three-way matching to audit Eskom’s systems to identify and account for fraudulent prepaid electricity tokens.
This involves comparing the tokens generated by the online vending system, what Eskom is billing customers, and its financial reporting.
According to Marokane, this showed there had been a significant decrease in electricity theft through ghost vending.
He acknowledged that the problem is not resolved and that they were constantly discovering new challenges they needed to manage.
Marokane highlighted “big ticket tokens” that were generated in the earlier part of their investigation as a particular challenge they were focusing on.
“We are focusing on developing a new solution that we want to bring on board. That’s what I’ll share at this point in time. It is a matter that is fully on our radar,” Marokane said.