A group calling itself Nullsec Nigeria, also posting as Anonymous Nigeria, says it pulled roughly 11GB of documents out of South African government systems and will keep leaking unless attacks on Nigerians living in South Africa stop. The claim landed on Telegram and hacker forums under the hashtag #OpSouthAfrica, and according to MyBroadband reporting on 17 May 2026, the files allegedly touch the Department of Correctional Services and the Ephraim Mogale Local Municipality. As of writing, no SA authority has confirmed a deep compromise, and no forensic report exists. That gap between a loud claim and a confirmed breach is exactly where most South African organisations get the wrong lesson from a story like this.
What is happening, and what we could stand up
The campaign itself is real. Nullsec Nigeria has publicly posted threat statements, screenshots, links to alleged leaked files, and political messaging tied to anti-foreigner violence in South Africa. Some of the shared material reportedly resembled genuine SA procurement and municipal paperwork: tender notices, bid invitations, council resolutions, annual reports, and financial records. The two named targets are real organisations. The Department of Correctional Services runs the country's prison system with roughly 34,000 staff, and Ephraim Mogale is a working municipality in the Sekhukhune District of Limpopo.
That is where the firm ground ends. A threat actor posting documents online does not prove that internal systems were breached, and there are at least three explanations that all fit the same screenshots: a genuine intrusion, recycled files from an older exposure being republished as new, or data pulled from a third party rather than the named department directly. There has been no published indicator-of-compromise list, no ransomware note, no forensic confirmation, and no sign of operational shutdown. The political timing is the one piece that is not in dispute. The campaign surfaced during a period of anti-foreigner protests in South Africa that President Cyril Ramaphosa publicly condemned earlier in May 2026, which points to a campaign built around pressure and visibility rather than money.
Why this lands harder in South Africa
South African government and public systems have been a softening target for a while, and this is not the first politically flavoured hit. In late January 2025 the South African Weather Service was knocked offline by an attack from an unknown source, which took down its website, email, and aviation and marine forecasts, and the disruption reached Mozambique and Zambia, which rely on SA forecasts, according to DefenceWeb reporting republished from the Africa Defense Forum. Cyberattacks across the continent rose 37% in 2024 compared to 2023, citing Check Point figures in the same report. The pattern around #OpSouthAfrica fits that trend rather than breaking from it.
The local sting is in the document type. Tender records, bid notices, supplier lists, and council resolutions look dull, which is exactly why people underrate them. Those files expose email formats, signatures, banking details, supplier relationships, and internal approval chains, and that is the raw material for the business email compromise and supplier-impersonation fraud that already drives a large share of SA losses. Under POPIA, the organisation that held the personal information carries the duty to apply reasonable safeguards and to report a breach to the Information Regulator and affected people, and that obligation does not wait for a hacker to publish a forensic report. If your business sits in a government or municipal supply chain, your details may already be inside paperwork you have no control over.
What to do this week
The honest position on the Nullsec claims is that they are unverified, so treat the campaign as a prompt to check your own exposure rather than a reason to panic about someone else's.
- Map where your data actually lives. Payroll provider, accounting firm, cloud storage, every municipal and government platform you have ever submitted a tender or invoice to. Each one is part of your attack surface whether you think about it or not. Write the list down.
- Turn on multi-factor authentication everywhere it is offered, starting with email and any account that can move money or change banking details. Most supplier-fraud cases begin with one mailbox the attacker can read quietly for weeks.
- Audit third-party and vendor access. Remove logins for suppliers and ex-staff you no longer work with, and restrict admin rights to the people who genuinely need them today, not the people who needed them last year.
- Patch and back up on a schedule you can prove. Consistent patching closes the openings these campaigns scan for, and offline backups are the difference between a bad week and a closed business if a leak turns into something destructive.
- Decide now who speaks if you are named in a leak. Silence during an incident lets fake screenshots and rumour fill the space, and the threat actor ends up writing your story for you. A one-page plan naming who confirms facts, who contacts the Information Regulator, and who talks to clients is enough to start.
Where Ubuntu Guard fits
If you have been named in a leak, think you have been hit, or simply cannot tell whether the documents floating around belong to you, that is the situation we handle. We treat it as a confirmed compromise until the evidence says otherwise, work from a clean device, and give you a plain-language report and a defensible response path, including what POPIA requires you to do and by when. We speak human, not tech jargon, and we do it on-site where it helps. You can read how we work at our incident response service.
Had a breach or think you have been hit? WhatsApp us now, we respond fast. Otherwise reach us at [email protected].
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za