The Compensation Fund has lost more money to fraud in the past two years than it lost in the decade before that. An institution built to pay injured workers, the people who fell off scaffolding, got burned in a factory fire, or lost a limb on a building site, was looted while auditors raised flag after flag that nobody in management appears to have read. The method behind it is the same one being run against South African businesses every week.
What the Auditor-General found
The Office of the Auditor-General of South Africa (AGSA) has handed the Compensation Fund a disclaimer audit opinion for close to 15 consecutive years. A disclaimer means the financial statements are so unreliable that no opinion can be formed on them at all. AGSA's Kgabo Komape told Parliament in May 2026 that transparency at the organisation is, in his words, completely non-existent.
The 2024-25 management report sets out how that plays out in practice. Auditors found material gaps between the fund's financial statements, its trial balances, and the documents that should support them, and in many cases those supporting documents were either missing or handed over too late to verify. Hundreds of millions of rands in payments went to medical service providers with no supporting documentation at all, according to The Citizen on 20 May 2026.
The fraud that drove the losses worked through a mechanism any business owner who has ever approved a supplier payment should find uncomfortable. Banking details stored on the fund's own system were changed so that payments were redirected to accounts the criminals controlled. When auditors tried to trace who made those changes, they found the audit log, the system record of who enters the platform and what they alter, had been switched off. Where users could be identified, they told auditors their accounts had been hacked and the changes were not made by them (GroundUp, February 2025). The system held its data unencrypted, and internal network testing turned up 220 vulnerabilities, 52 of them critical and another 73 rated high risk.
A senior internal source told The Citizen the system had been built to enable looting. That allegation is unproven. What the auditors put on the record, unencrypted systems, disabled logs, and weak control over who can change what, describes an organisation running with no working controls.
Why this matters for your business
Most people reading this do not file claims with the Compensation Fund, so the reason to care is the method, because it maps almost exactly onto the fraud hitting SA companies right now.
The technique is bank account takeover fraud, and it sits behind the Business Email Compromise (BEC) attacks that cost South African businesses heavily every year. Someone, an outsider who has taken over a user account or an insider with system access, changes the banking details on a supplier or creditor record. The next legitimate payment lands in their account instead of the real supplier's. By the time anyone reconciles the books, the money has moved and the trail has gone cold.
POPIA, the Protection of Personal Information Act, puts a legal duty on any organisation holding personal information to apply reasonable safeguards. The Compensation Fund holds sensitive data on injured workers across the country, and the audit record shows its safeguards fell well short of reasonable. That same standard runs against your business, and reasonable safeguards means the exact controls the fund let lapse: access logs that are switched on and read, encrypted records, a verified process for changing banking details, and a way to catch an unauthorised change before the payment runs.
The audit trail is also a lesson in what happens when nobody acts. The fund has failed its audit for close to 15 years, and its annual fraud losses roughly quadrupled across two financial years (The Citizen and EWN, May 2026). Control failures that go unaddressed do not hold steady, they widen, because the people working them grow more confident the longer nobody is watching.
What to do this week
You cannot fix the Compensation Fund. You can close the same gaps in your own business, on the exact controls it failed.
- Lock down who can change banking details. Any change to a supplier's stored bank account should need two people to approve it, plus a verification call to the supplier on a number you hold on file, never the number printed on the change request itself. If one person can edit a bank account and release the next payment on their own, that is your single biggest exposure.
- Switch your audit logs on, and read them. A log nobody opens is not a control. Set a monthly review at minimum: who logged in, what they changed, and whether any edit to financial records or user permissions happened outside working hours. Most account takeover damage is visible in the logs days before the money moves.
- Run an access check every quarter. Every former employee, ex-contractor, or old supplier contact still holding a login is a way in. Compare active accounts against your current staff and supplier list, and remove access on the day someone leaves rather than the week after.
- Confirm your sensitive records are encrypted. If your accounting, payroll, or HR platform stores personal or financial data and you cannot say whether it is encrypted at rest, ask your IT provider or software vendor to confirm it in writing today.
- Know your POPIA position before something goes wrong. Map what personal information sits in your payment and accounting systems and who can reach it. If that information is ever compromised, you are required to notify the Information Regulator and the affected people as soon as reasonably possible, and the time to decide who handles that is now, before an incident forces the question.
Where Ubuntu Guard fits
If you cannot say for certain whether your payment controls, access management, and logging would catch a changed banking detail, that is the ground our cybersecurity assessment covers. We look at the real state of your systems, what is switched on and working rather than what the policy says should be there, and hand you a plain-language report and a ranked action list within 48 hours, including where your POPIA obligations sit given your current setup. No jargon, no alarmism.
If you are not certain your business would catch a supplier's banking details being changed under your nose, that is exactly what the assessment checks. WhatsApp us to book: wa.me/27791595040, or reach us at [email protected].
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za