{"id":653564,"date":"2026-06-19T11:01:31","date_gmt":"2026-06-19T09:01:31","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=653564"},"modified":"2026-06-19T11:03:04","modified_gmt":"2026-06-19T09:03:04","slug":"anc-investigates-black-x-hack-senior-executive-may-be-included","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/653564-anc-investigates-black-x-hack-senior-executive-may-be-included.html","title":{"rendered":"ANC investigates Black X hack \u2014 &#8220;Senior executive may be included&#8221;"},"content":{"rendered":"\n<p>The African National Congress (ANC) has launched an investigation following claims its systems were breached by the hacker group known as Black X.<\/p>\n\n\n\n<p>It said that it was engaging with the South African Police Service (SAPS) and the State Security Agency (SSA) as the affected data &#8220;may include senior executive members in cabinet and state.&#8221;<\/p>\n\n\n\n<p>On 14 May, MyBroadband reported on <a href=\"https:\/\/mybroadband.co.za\/news\/security\/647594-anc-hit-by-data-breach-2-million-private-member-records-exposed.html\" target=\"_blank\" rel=\"noreferrer noopener\">claims made by Black X<\/a>, and data samples the group shared were purported to be private data of ANC members.<\/p>\n\n\n\n<p>Dimitri Fousekis, chief technology officer and co-founder of South African cybersecurity firm Bitcrack Cyber Security, told MyBroadband that the leak appeared to be authentic.<\/p>\n\n\n\n<p>However, he said it was impossible to say how much data had been acquired, since the full extent of the leak could not be determined. Black X demanded a hefty sum for the database.<\/p>\n\n\n\n<p>When we initially reported on the alleged breach, we contacted the ANC for comment. The party did not respond to our queries and instead publicly denied the breach in a post on X\/Twitter.<\/p>\n\n\n\n<p>In the post, the ANC said that reports about the breach were &#8220;fake news&#8221; and called them &#8220;sensationalist.&#8221;<\/p>\n\n\n\n<p>&#8220;The ANC cautions against reckless speculation and the circulation of unverified claims designed to create unnecessary panic, fear, and political mischief,&#8221; it said at the time.<\/p>\n\n\n\n<p>A report by infostealer intelligence firm Hudson Rock then suggested that a malware infection had been linked to the ANC&#8217;s Internet domain.<\/p>\n\n\n\n<p>Infostealers are viruses that infect computers and harvest sensitive user data. Some just steal login credentials, while others may exfiltrate private keys for crypto wallets and other financial information.<\/p>\n\n\n\n<p>Responding to a follow-up query about the Hudson Rock report, the ANC told MyBroadband that it was aware of Black X&#8217;s claims of a data breach.<\/p>\n\n\n\n<p>&#8220;The ANC&#8217;s service provider, Emperio, undertook a Preliminary Security Incident Assessment in the immediate aftermath of the claim,&#8221; it said.<\/p>\n\n\n\n<p>Emperio completed the report and sent it to the Office of the Secretary General, after which the office considered the report and briefed the National Working Committee on the findings.<\/p>\n\n\n\n<p>&#8220;Emperio&#8217;s preliminary investigation identified no conclusive evidence of unauthorised access to the current production database under Emperio&#8217;s management,&#8221; the ANC said.<\/p>\n\n\n\n<p>&#8220;The threat claim is more consistent with an opportunistic threat or extortion attempt, or with possible historical data exposure predating Emperio&#8217;s current hosted environment, than with a verified breach.&#8221;<\/p>\n\n\n\n<p>The ANC said it had been in communication with the Information Regulator of South Africa since 15 May about the potential breach of private member data.<\/p>\n\n\n\n<p>&#8220;The Regulator recorded that it became aware of a possible security compromise on or about 15 May 2026 and set in motion the standing engagement protocol on its side,&#8221; the party said.<\/p>\n\n\n\n<p>&#8220;Engagement extends, on the ANC&#8217;s instance to SAPS report and SSA alert as the past data may include senior executive members in cabinet and state.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">ANC in communication with the Information Regulator<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/03\/POPIA-Estates-Gate-Guards-Pansy-1200x675.jpg\" alt=\"\" class=\"wp-image-637220\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/03\/POPIA-Estates-Gate-Guards-Pansy-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/03\/POPIA-Estates-Gate-Guards-Pansy-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/03\/POPIA-Estates-Gate-Guards-Pansy-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/03\/POPIA-Estates-Gate-Guards-Pansy-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/03\/POPIA-Estates-Gate-Guards-Pansy.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Pansy Tlakula, Information Regulator chairperson<\/figcaption><\/figure>\n\n\n\n<p>The Information Regulator told MyBroadband that the party had not formally reported a security compromise as required in section 22 of POPIA.<\/p>\n\n\n\n<p>This section states that custodians of private data must inform the regulator if outside actors have potentially compromised people&#8217;s data.<\/p>\n\n\n\n<p>However, the party and the regulator were engaged in ongoing communications related to the Black X breach claims.<\/p>\n\n\n\n<p>&#8220;The ANC, following our communication to them, responded extensively, and we are still processing and considering their submission,&#8221; the regulator said.<\/p>\n\n\n\n<p>&#8220;We will thereafter determine the way forward or the course of action we will take.&#8221;<\/p>\n\n\n\n<p>The party said that, through Emperio, its ICT provider, it has taken measures to strengthen its standing security architecture.<\/p>\n\n\n\n<p>This began with rotating passwords and credentials and applying additional security patches on its official domain, which the hacker group said it targeted.<\/p>\n\n\n\n<p>&#8220;Administrative access exposure, including Remote Desktop Protocol (RDP) access, has been reviewed with a focus on restricting access to trusted sources only,&#8221; the ANC said.<\/p>\n\n\n\n<p>&#8220;Server and database configuration areas associated with higher risk have been reviewed \u2014 privileged access, SQL logins, suspicious changes, backup and export indicators, and high-risk features.&#8221;<\/p>\n\n\n\n<p>Emperio was also engaged in ongoing monitoring and log review to identify any new evidence or indicators of compromise that may arise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Existing vulnerabilities on the ANC&#8217;s systems<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Fousekis-AWS.jpg\" alt=\"\" class=\"wp-image-647066\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Fousekis-AWS.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Fousekis-AWS-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Fousekis-AWS-768x432.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Dimitri Fousekis, co-founder and CTO of Bitcrack Cyber Security<\/figcaption><\/figure>\n\n\n\n<p>At the same time, the Office of the Secretary General commissioned a separate External Risk Assessment scan of the party&#8217;s public-facing domains and IP addresses.<\/p>\n\n\n\n<p>&#8220;That scan, dated 15 May 2026, has surfaced a discrete set of pre-existing hygiene exposures \u2014 historical credentials drawn from old third-party breaches,&#8221; it said.<\/p>\n\n\n\n<p>It also found typo-squatting domains targeting the ANC&#8217;s brand, and outdated security configurations across parts of the public-facing estate. &#8220;These exposures are being remediated,&#8221; it said.<\/p>\n\n\n\n<p>However, it said these exposures are unrelated to claims made by Black X, as they are separate from the membership system the hacker group said it breached.<\/p>\n\n\n\n<p>An independent analysis by cybersecurity firm Hudson Rock <a href=\"https:\/\/www.hudsonrock.com\/search\/domain\/anc1912.org.za\" target=\"_blank\" rel=\"noreferrer noopener\">found<\/a> at least two infostealer malware programs on the ANC&#8217;s domain.<\/p>\n\n\n\n<p>In addition to harvesting login credentials, infostealers can hide on computers and quietly collect other data to send to attackers, such as member records.<\/p>\n\n\n\n<p>Hudson Rock indicated that it identified two infostealers: one called DarkCrystal and the other generic. DarkCrystal is a notable infostealer delivered by a trojan.<\/p>\n\n\n\n<p>Trojans require victims to install malware on their own machines. Much like the mythological Trojan Horse, attackers trick victims into running the malicious software in some way.<\/p>\n\n\n\n<p>Security researchers at SOC Prime explained that the DarkCrystal Remote Access Trojan, also known as DCRat or DCR, was used by Russia-linked hackers to target Ukrainian businesses in 2022.<\/p>\n\n\n\n<p>However, it also indicated a potential problem with the Hudson Rock analysis, as DarkCrystal has only been associated with targeting end-user machines, not servers.<\/p>\n\n\n\n<p>The ANC said that Hudson Rock&#8217;s analysis does not immediately indicate a breach of the Membership Management System and is more likely to point to a compromise of an individual user.<\/p>\n\n\n\n<p>Fousekis said that the presence of infostealers could be potentially related to the breach claims by Black X, but could not confirm this. <\/p>\n\n\n\n<p>&#8220;A leaked credential can give access into an application, thus creating an initial foothold required to exploit the system further, following which they could have got access through a vulnerability of some kind,&#8221; he said.<\/p>\n\n\n\n<p>He said that it was unlikely an infostealer like DarkCrystal was on the ANC&#8217;s servers, and that, as the ANC indicated, the most common occurrence is user device compromise.<\/p>\n\n\n\n<p>&#8220;However, if someone is using the server for &#8216;Desktop&#8217; type activities, they could have infected it as well,&#8221; said Fousekis.<\/p>\n\n\n\n<p>&#8220;Our threat intelligence tool ThreatVue shows leaked credentials as current as June 2026 for this domain, which means that there are stealers active on users&#8217; devices who have access to this domain.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The ANC told MyBroadband that it was expanding its investigation into claims that it was hacked, saying that potentially affected data could include senior executive members in cabinet and state.<\/p>\n","protected":false},"author":341213,"featured_media":653569,"comment_status":"open","ping_status":"closed","sticky":true,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[13397,569,105348,15227,105856,26872,105175,14575,66803,101978,7311,90134],"class_list":["post-653564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-african-national-congress","tag-anc","tag-black-x","tag-cybersecurity","tag-darkcrystal","tag-data-breach","tag-dimitri-fousekis","tag-hack","tag-information-regulator-of-south-africa","tag-infostealer","tag-leak","tag-sandworm"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/653564"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341213"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=653564"}],"version-history":[{"count":15,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/653564\/revisions"}],"predecessor-version":[{"id":654736,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/653564\/revisions\/654736"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/653569"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=653564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=653564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=653564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}