{"id":644958,"date":"2026-05-04T10:01:51","date_gmt":"2026-05-04T08:01:51","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=644958"},"modified":"2026-05-04T10:05:46","modified_gmt":"2026-05-04T08:05:46","slug":"obvious-security-flaw-in-website-of-important-r54-billion-south-african-fund","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/644958-obvious-security-flaw-in-website-of-important-r54-billion-south-african-fund.html","title":{"rendered":"Obvious security flaw in website of important R54-billion South African fund"},"content":{"rendered":"\n<p>The official website for the National Student Financial Aid Scheme (NSFAS) no longer has a valid Transport Layer Security (TLS) certificate, hindering students from accessing the site.<\/p>\n\n\n\n<p>According to the security details on the website,&nbsp;nsfas.org.za, it expired on Friday, 1 May 2026. Without a valid TLS certificate, communication between users and the web server is unencrypted.<\/p>\n\n\n\n<p>NSFAS is one of the largest payment facilitators in South Africa, processing monthly payments for over a million beneficiaries. It has a budget of R54 billion for the 2026\/2027 financial year.<\/p>\n\n\n\n<p>The inability to renew its TLS certificate, a routine security process, points to a larger, systemic problem with the agency&#8217;s cybersecurity protocols.<\/p>\n\n\n\n<p>TLS certificates provide digital validation and encryption of a website&#8217;s online identity. They are used to secure connections between user browsers and an organisation&#8217;s webpages.<\/p>\n\n\n\n<p>When certificates expire, connections between browsers and websites are no longer secure, and any sensitive data transmitted may be at risk of interception from threat actors.<\/p>\n\n\n\n<p>That means data such as login credentials, payment information, or personal details may be exposed and stolen, according to certificate vendor Sectigo.<\/p>\n\n\n\n<p>&#8220;Modern web browsers will display warning messages to users attempting to access a site with an expired security certificate,&#8221; the company explained.<\/p>\n\n\n\n<p>&#8220;This can erode users&#8217; trust and deter visitors from continuing to the site, potentially leading to a loss of traffic and credibility.&#8221;<\/p>\n\n\n\n<p>When tested on Monday morning, Google Chrome prevented users from accessing the main NSFAS website. The site was flagged as &#8220;untrusted.&#8221;<\/p>\n\n\n\n<p>The my.nsfas.org.za portal appeared to have a valid certificate and remained accessible. This indicated that beneficiaries could still access their accounts without the threat of interception.<\/p>\n\n\n\n<p>However, any support resources, including student loans, student accommodation, important forms, information on the appeal process and more, are difficult to access due to the expired certificate.<\/p>\n\n\n\n<p>Users could still access the site by bypassing their browser&#8217;s security block via the &#8220;advanced options&#8221; available on the warning page, but they would do so at their own risk.<\/p>\n\n\n\n<p>Dr Karen Stander, former chair of the scheme&#8217;s board of directors, said in August 2025 that NSFAS&#8217;s ICT systems were constantly at risk due to poor security procedures.<\/p>\n\n\n\n<p>&#8220;The organisation&#8217;s ICT systems are misaligned with business requirements and lack integration,&#8221; she said during a media briefing.<\/p>\n\n\n\n<p>She said that the scheme&#8217;s lacking ICT systems exposed troves of private information from students to &#8220;severe cybersecurity risks.&#8221;<\/p>\n\n\n\n<p>In 2024, the Portfolio Committee on Higher Education recommended that NSFAS <a href=\"https:\/\/www.parliament.gov.za\/press-releases\/media-statement-higher-education-committee-receives-briefing-nsfas\">strengthen its ICT systems<\/a> as a matter of urgency &#8220;to curb student data falling into the wrong hands.&#8221;<\/p>\n\n\n\n<p>Tebogo Letsie, chairperson of the committee, said the department must conduct a forensic investigation into the National Treasury funds allocated to the scheme to improve its ICT systems.<\/p>\n\n\n\n<p>MyBroadband contacted NSFAS upon discovering the expired TLS certificate, but did not receive a response by publication.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Student discovered security vulnerability at NSFAS<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/12\/Jordan-and-Connor-Bettridge.jpg\" alt=\"\" class=\"wp-image-623369\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/12\/Jordan-and-Connor-Bettridge.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/12\/Jordan-and-Connor-Bettridge-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2025\/12\/Jordan-and-Connor-Bettridge-768x432.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Jordan Bettridge (left) and Connor Bettridge (right).<\/figcaption><\/figure>\n\n\n\n<p>In 2025, a Varsity College student <a href=\"https:\/\/mybroadband.co.za\/news\/security\/623367-south-african-university-student-uncovers-security-flaw-in-critical-financial-system.html\">discovered a vulnerability<\/a> in the scheme&#8217;s ICT systems that, if exploited, would allow attackers to access highly sensitive services.<\/p>\n\n\n\n<p>The vulnerability could allow attackers to take over an administrative user account with which they could approve or reject funding applications and access sensitive financial information.<\/p>\n\n\n\n<p>The student, Connor Bettridge, first discovered the vulnerability after he noticed that a panel on the scheme&#8217;s web portal displayed every message sent by the system to every user.<\/p>\n\n\n\n<p>This included one-time PINs (OTPs) that were generated and sent to people who had forgotten their passwords.<\/p>\n\n\n\n<p>Bettridge continued digging after discovering this flaw and found that the website&#8217;s API was extremely poorly secured.<\/p>\n\n\n\n<p>Bettridge then brought in his older brother, Jordan, to help him investigate for further vulnerabilities. The pair discovered the extent to which an attacker could exploit the NSFAS API.<\/p>\n\n\n\n<p>They revealed how a threat actor could exploit the API to rapidly download private information from the millions of students who used the system in the past three years.<\/p>\n\n\n\n<p>A more critical vulnerability discovered by the pair showed how an attacker could use the API to gain administrative access to the NSFAS webpage.<\/p>\n\n\n\n<p>&#8220;NSFAS became aware of a potential security weakness and immediately activated its information security and incident management protocols,&#8221; said NSFAS after the vulnerability was reported.<\/p>\n\n\n\n<p>&#8220;The matter was prioritised, investigated, and appropriate remedial actions were implemented without delay.&#8221;<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">NSFAS website blocking access to students<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-1-1200x675.jpg\" alt=\"\" class=\"wp-image-644982\" style=\"width:840px;height:auto\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-1-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-1-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-1-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-1-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-1.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-2-1200x675.jpg\" alt=\"\" class=\"wp-image-644978\" style=\"width:840px;height:auto\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-2-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-2-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-2-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-2-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/NSFAS-security-flaw-2.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><em>Pictured in article thumbnail: Waseem Carrim, Acting Chief Executive Officer of NSFAS<\/em>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An obvious cybersecurity flaw is preventing students from accessing the official NSFAS website, pointing to deeper issues at the scheme. <\/p>\n","protected":false},"author":341213,"featured_media":644959,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[104983,15227,102674,101213,104982,39608,104984,5106,104100],"class_list":["post-644958","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-conner-bettridge","tag-cybersecurity","tag-jordan-bettridge","tag-karen-stander","tag-national-student-financial-aid-scheme","tag-nsfas","tag-tebogo-letsie","tag-tls","tag-tls-certificate"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/644958"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341213"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=644958"}],"version-history":[{"count":10,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/644958\/revisions"}],"predecessor-version":[{"id":644991,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/644958\/revisions\/644991"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/644959"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=644958"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=644958"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=644958"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}