Security24.05.2026

Nigerian hacking group claims it breached SARS

Threat actor Nullsec Nigeria claims to have breached the South African Revenue Service (SARS) and South African Information Technology Agency (SITA).

The hacktivist group, which also goes by Anonymous Nigeria, posted links to download the alleged compromised data on the Breached hacker forum on 23 May 2026.

It claimed the SARS data contained names, email addresses, and passwords used on sars.gov.za. The SITA download allegedly included names, passwords, and platforms of entry to SITA services.

A subset of the information included many email addresses with domains of US companies, including Apple.com.

A South African cybersecurity researcher who analysed the data does not believe Nullsec Nigeria’s claims were substantiated.

“In my opinion, there is not enough information to confirm the SARS and SITA breach claims are real,” they told MyBroadband.

MyBroadband also asked SARS and SITA for feedback. The taxman had not provided comment by the time of publication, but SITA spokesperson Tlali Tlali denied the claims.

SITA head of corporate affairs Tlali Tlali said the entity’s ICT infrastructure remained fully intact and was not compromised.

“There is no evidence of any unauthorised access to government data or systems, nor has any breach of security occurred through unlawful methods,” he said.

SITA said its security operations teams operated on a continuous, 24/7 basis and were equipped with monitoring and threat-detection capabilities. 

“We run a multi-tiered scan of our security environment, and we are satisfied that there are grounds to refute these claims,” it said.

“All systems have been tested and verified as fully operational, and no anomalies indicative of a cyberattack have been identified.”

SITA said the misinformation regarding the security of government systems posed a risk not only to public confidence but also to the integrity of national digital infrastructure.

“We advise all parties to rely on official communications from SITA and the relevant government departments as the authoritative source of information regarding the status and security of government ICT systems,” Tlali said.

SAPS website offline

Tlali acknowledged that one government department’s website was unavailable at the time of its feedback.

“We wish to clarify that the downtime of a website of that department is the direct result of a scheduled and planned maintenance window,” Tlali said.

He explained the work included system upgrades and enhancements intended to improve the performance, resilience, and security of the department’s online presence.

While Tlali did not name the department, the South African Police Service (SAPS) website was inaccessible at various points on Saturday, 23 May and Sunday, 24 May.

Users visiting the site were presented with a “This site can’t be reached” error. Nullsec Nigeria’s claim that it would target SAPS earlier in the week led to speculation the downtime was part of its handiwork.

Nullsec Nigeria last week also claimed it breached the Department of Correctional Services systems and accessed information on tenders.

The group maintained that its actions against South African entities were in response to xenophobic attacks against African and Asian immigrants.

It asserted its activity was not intended to harm everyday South Africans but was aimed at “exposing” governance failures.

It criticised reports that it had locked any compromised files and demanded payment, like a malicious actor would in a ransomware attack.

One country evacuates its citizens

Middle Eastern and African refugees in South Africa protesting in Cape Town in 2019

The recent wave of xenophobic activity evoked sharp criticism from the governments of the most heavily impacted foreign nationals.

The government of Ghana issued an evacuation notice for its citizens in South Africa on 18 May 2026. It has promised to fund the flights of hundreds of Ghanaians back to their home country.

Human Rights Watch (HRW) has highlighted that South Africa has been the scene of intermittent but widespread xenophobic harassment and violence against African and Asian foreign nationals.

The sporadic waves started in 2008, when 62 people, including 21 South Africans, 11 Mozambicans, 5 Zimbabweans and 3 Somalis, were killed amid intense clashes between locals and foreigners.

The HRW has condemned “little or insufficient apparent response” from the police and other authorities to the xenophobic activity in 2026, which began after the March and March protests.

It highlighted the roles of “vigilantes” motivated by campaigns from entities including Operation Vulindlela.

“These groups scapegoat foreign nationals as the cause of South Africa’s economic woes, poor service delivery, and high rates of crime, despite studies that disprove these claims,” HRW said.

HRW South Africa researcher Nomathamsanqa Masiko-Mpaka called for intensified efforts to address anti-immigrant sentiments and violence to ensure the safety and protection of at-risk foreign nationals.

“Vigilante groups need to be held fully accountable, including through effective criminal prosecutions,” Masiko-Mpaka said.

“The authorities should not allow vigilante groups to violently target foreign nationals and instead need to protect them and bring those who harm them to justice.”

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter