{"id":605080,"date":"2025-08-02T09:56:39","date_gmt":"2025-08-02T07:56:39","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=605080"},"modified":"2025-08-02T10:00:34","modified_gmt":"2025-08-02T08:00:34","slug":"two-south-african-broadcasters-hit-by-cyberattack","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/broadcasting\/605080-two-south-african-broadcasters-hit-by-cyberattack.html","title":{"rendered":"Two South African broadcasters hit by cyberattack"},"content":{"rendered":"\n<p>Staff members at the SABC and eMedia have fallen victim to business email compromises, which resulted in phishing emails being sent to their contact lists.<\/p>\n\n\n\n<p>The attack had been circulating around the SABC since at least Monday, when the address of a stakeholder relationships and partnerships manager sent a phishing email to contacts outside the organisation.<\/p>\n\n\n\n<p>The attack email adopted a simple approach. It contained a PDF attachment, which it encouraged the recipient to click on.<\/p>\n\n\n\n<p>Upon opening the attachment, the reader was presented with the blurry image of what appears to be a statement on a prominent bank\u2019s letterhead, with a message to click to access the document.<\/p>\n\n\n\n<p>Closer examination of the PDF revealed that it was purely a link to a website on top of a blurry image. Clicking the link took the victim to an attack site.<\/p>\n\n\n\n<p>The attack site aimed to gain access to the victim\u2019s email account and spread by sending itself to their address book.<\/p>\n\n\n\n<p>MyBroadband <a href=\"https:\/\/mybroadband.co.za\/news\/broadcasting\/604864-sabc-hacked.html\">received a second attack email<\/a> from a different SABC executive on Thursday. On Friday, the virus had infected the email account of a senior executive at eNCA.<\/p>\n\n\n\n<p>An eMedia spokesperson confirmed the attack and said it had been isolated to that single individual\u2019s email account.<\/p>\n\n\n\n<p>\u201cThe situation was contained quickly, and no broader evidence of business email compromise affecting eNCA at this stage,\u201d they said.<\/p>\n\n\n\n<p>&#8220;The affected user account was secured, and our Infrastructure and Security teams responded right away to investigate and contain the incident.\u201d<\/p>\n\n\n\n<p>eMedia said it took immediate steps to ensure its IT environment remained safe, and precautionary measures were reinforced.<\/p>\n\n\n\n<p>Asked whether the SABC and eNCA attacks were related, eMedia said they appeared connected. \u201cThe email that led to the compromise originated from a compromised SABC account,\u201d they said.<\/p>\n\n\n\n<p>\u201cAn eNCA employee received and engaged with the message, which led to the incident. It suggests the attack may have been part of a wider phishing attempt across multiple organisations.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Interpol warning<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"801\" height=\"800\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/08\/BEC-SABC-eNCA-801x800.jpg\" alt=\"\" class=\"wp-image-605082\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/08\/BEC-SABC-eNCA-801x800.jpg 801w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/08\/BEC-SABC-eNCA-400x400.jpg 400w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/08\/BEC-SABC-eNCA-768x767.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/08\/BEC-SABC-eNCA.jpg 807w\" sizes=\"(max-width: 801px) 100vw, 801px\" \/><figcaption class=\"wp-element-caption\">Screenshot of the phishing email sent to executives at the SABC and eNCA<\/figcaption><\/figure>\n\n\n\n<p>Cybercriminal groups are increasingly targeting South African businesses, state-owned entities, and government departments.<\/p>\n\n\n\n<p>Interpol recently released its Africa Cyberthreat Assessment Report 2025, which found that South Africa is a top target for cybercriminals operating on the continent.<\/p>\n\n\n\n<p>Regarding business email compromise (BEC), Interpol member countries in Africa have identified the attack as a significant and growing cyberthreat within the broader landscape of online scams.<\/p>\n\n\n\n<p>\u201cData from Interpol\u2019s private sector partners indicate a sharp rise in BEC-related cybercriminal activity across Africa, both in attack volume and financial impact,\u201d it stated.<\/p>\n\n\n\n<p>\u201cA substantial number of BEC criminals operate from the continent, particularly in West Africa.\u201d<\/p>\n\n\n\n<p>According to data from Interpol private partners, eleven African nations account for most BEC activity originating from the continent, with a concentration in Nigeria, Ghana, C\u00f4te d\u2019Ivoire, and South Africa.<\/p>\n\n\n\n<p>In West Africa, some criminal networks have evolved into highly organised, multi-million-dollar enterprises driven by BEC fraud.<\/p>\n\n\n\n<p>The transnational syndicate Black Axe has thousands of members worldwide and is responsible for large-scale financial scams that have generated billions.<\/p>\n\n\n\n<p>Data provided by Interpol African member countries indicated that in 2024, the finance sector was the most frequently targeted.<\/p>\n\n\n\n<p>Companies engaged in international trade, frequent financial transactions, and those with underdeveloped security controls were particularly vulnerable to BEC attacks.<\/p>\n\n\n\n<p>However, no industry was immune to BEC attacks. Organisations of all sizes, from small and medium-sized enterprises to large corporations, were affected.<\/p>\n\n\n\n<p>\u201cIn addition to banks and microfinance institutions, significant incidents were reported in sectors such as the import and export trade, oil and gas, pharmaceuticals, transport, and e-commerce,\u201d Interpol warned.<\/p>\n\n\n\n<p>\u201cAttacks on government institutions, as well as the voluntary sector and individuals, were also on the rise across the continent.\u201d<\/p>\n\n\n\n<p>Unfortunately, precise numbers of BEC incidents in Africa are challenging to obtain due to underreporting. However, several indicators reveal the scale of the problem.<\/p>\n\n\n\n<p>\u201cIn 2024 alone, 19 African countries collectively reported 10,490 cybercrime-related arrests, suggesting that the actual number of BEC cases is significantly higher, given that only an estimated 35% of cybercrimes are officially reported,\u201d Interpol said.<\/p>\n\n\n\n<p>The type of BEC attack the SABC and eNCA fell victim to appear to be an example of cybercrime- as-a-Service (CaaS), which Interpol said was fueling the growing sophistication of BEC attacks.<\/p>\n\n\n\n<p>\u201cMicrosoft\u2019s Digital Crimes Unit detected a 38% increase in CaaS targeting business email accounts between 2019 and 2022,\u201d it said.<\/p>\n\n\n\n<p>\u201cThreat actors now have access to ready-made phishing kits, allowing them to scale operations efficiently.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Staff members at the SABC and eMedia have fallen victim to business email compromises, which resulted in phishing emails being sent to their contact lists.<\/p>\n","protected":false},"author":15,"featured_media":423698,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[24,27],"tags":[68042,51025,19001,9315,19949],"class_list":["post-605080","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-broadcasting","category-security","tag-business-email-compromise-bec-fraud","tag-emedia","tag-enca","tag-interpol","tag-south-african-broadcasting-corporation-sabc"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/605080"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=605080"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/605080\/revisions"}],"predecessor-version":[{"id":605083,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/605080\/revisions\/605083"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/423698"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=605080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=605080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=605080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}