OpSouthAfrica Explained: The Nullsec Nigeria Hack Claims Investigated

By Ubuntu Guard | 30 May 2026 TLP:CLEAR

In the second half of May 2026, a Nigerian hacktivist crew called Nullsec Nigeria claimed to have breached nine South African government agencies in a single week: SARS, SITA, the Department of Correctional Services, SACAA, SANSA, SASSA, the Department of Human Settlements, the National Housing Finance Corporation, and Ephraim Mogale Local Municipality. The hashtag was #OpSouthAfrica. The distribution channels were the dark-web forum Breached, a branded Telegram channel, and amplification through X.

SARS denied it within hours, and SITA followed with a statement more technically detailed than most South African agencies manage when they have a real incident to contain. Independent researchers who examined the published file structures found the payload consistent with recycled infostealer logs, not a direct network compromise of either agency. On the available evidence, the SARS and SITA claims are almost certainly inflated.

The credentials in that dump came from somewhere. They still work wherever the same passwords were reused. Your organisation's exposure depends on how many of your staff or suppliers were in that data, and most South African businesses have no way of knowing right now.

What the evidence shows about the OpSouthAfrica breach claims

The crew published their claims in stages between 17 and 25 May, staging each release for maximum media coverage. Three other handles appeared in subsequent reporting alongside Nullsec Nigeria: 404 Crew, Infernalis, and Nullsec Philippines. None of the three have verifiable independent histories in the SA context. The most credible reading is that these are the same operation under different names, or amplification accounts added to give the campaign a coalition appearance.

Campaign timeline

17 May 2026
MyBroadband publishes first report on Nullsec claim against DCS and Ephraim Mogale Local Municipality
18 May 2026
Daily Maverick expands target list to SACAA, SANSA, SASSA, NHFC, Dept of Human Settlements. Names 404 Crew and Infernalis
19 May 2026
Separate BlackMatter DDoS campaign begins hitting SA hosting providers (1-Grid, Xneelo, Network Platforms)
23 May 2026
MyBroadband follow-up: Nullsec claims SARS and SITA breach
24 May 2026
Brinztech threat alert names Nullsec Philippines as joint actor
25 May 2026
SITA issues public refutation (Tlali Tlali, head of corporate affairs)
25 May 2026
SARS issues public refutation: "false and unsubstantiated"
26 May 2026
Ubuntu Guard publishes full investigation

What Nullsec Nigeria claimed: target-by-target analysis

The most significant claim was a dump from SARS and SITA published between 23 and 25 May, purporting to contain names, email addresses, and cleartext passwords from the eFiling platform. Two things make that claim technically implausible. Modern login systems store password hashes, not plaintext passwords. Cleartext credentials in a dump almost always originate from infostealer malware running on a user's personal device, not from a server-side breach.

South African Revenue Service (SARS) Disputed

Claim: Database archive containing names, email addresses, and passwords from eFiling platform users. Distributed for free on Breached forum, 23 to 25 May 2026.

Response: SARS stated on 25 May 2026: "These claims are false and unsubstantiated. SARS continuously monitors its systems for any suspicious activity and has conducted a thorough investigation."

Technical note: Brinztech found no structural evidence of a direct network compromise and pointed to recycled credential aggregation as the more likely explanation.

Evidence rating: Disputed

State Information Technology Agency (SITA) Disputed

Claim: Names, passwords, and "platforms used to access SITA services". Distributed on Breached forum.

Response: "Our ICT infrastructure remains fully intact and has not been compromised. We run a multi-tiered scan of our security environment and are satisfied there are grounds to refute these claims."

Evidence rating: Disputed

Department of Correctional Services (DCS) Unverified

Claim: Sample of bid notices, tender results, council resolutions, annual report, and one handwritten tender document. Group claimed 11GB total.

Analysis: Most of the sample is material the government is legally required to publish. The handwritten tender is the outlier: it points to a misconfigured upload directory or internal access. DCS did not comment.

Evidence rating: Unverified

Ephraim Mogale Local Municipality Unverified

Claim: Website hacked. No sample data published. Group quote: "we'll expose everything you got."

Evidence rating: Unverified

SACAA, SANSA, SASSA, Dept of Human Settlements, NHFC Unverified

All five were listed without any published sample data. SANSA has a strong prior disclosure track record on confirmed incidents, making its silence a mild signal the current claim is not credible.

Evidence rating: Unverified (all five)

Why OpSouthAfrica matters beyond the government agencies named

The credentials in that dump came from somewhere. Whether Nullsec breached SARS or simply repackaged stolen credentials, those email addresses and passwords still work wherever the same password was reused.

I have spent more than twenty years running security assessments for South African organisations. The pattern at the centre of OpSouthAfrica is one I see consistently: the claim is about a government breach, but the underlying risk lands in the private sector.

Infostealer malware does not breach government servers. It runs silently on a personal laptop, harvests every saved browser password in under a minute, then disappears. The person whose credentials ended up in a Nullsec dump may have logged into eFiling from a home computer that downloaded cracked software two years ago. That credential sat in a broker's database, was bundled with thousands of others, and was eventually repackaged as part of a hacktivist claim for the news cycle. The underlying credential still works anywhere the same password was reused.

The DCS procurement sample adds a second concern. The dominant attack workflow against SA government and parastatal portals is to crawl public URLs, increment sequential record IDs, query API endpoints directly, and bundle whatever comes back. Access controls are enforced at the user interface layer. The underlying API returns records to anyone who knows the URL structure. In every portal audit I have run over the past three years, at least one of these exposure patterns was present.

What South African organisations should do right now

Where Ubuntu Guard fits

Ubuntu Guard provides credential exposure audits, procurement portal hardening reviews, and POPIA dry-run exercises for South African businesses and organisations. If OpSouthAfrica raised questions your security team cannot yet answer with confidence, those are the conversations we work through with clients.

Reach us at [email protected]

Frequently asked questions

Was the SARS data breach in May 2026 confirmed?

SARS issued a public denial on 25 May 2026, describing the claims as "false and unsubstantiated." Independent threat researchers who reviewed the file structure concluded the payload is more consistent with aggregated infostealer logs than a direct system compromise. The claim remains disputed.

What is OpSouthAfrica?

OpSouthAfrica was a hacktivist campaign run primarily by Nullsec Nigeria in May 2026, targeting South African government agencies in claimed retaliation for xenophobic attacks against Nigerians in South Africa. The group published data samples on the Breached forum and amplified claims through Telegram and X between 17 and 25 May 2026.

How is OpSouthAfrica different from the BlackMatter DDoS attack the same month?

The two ran concurrently but are entirely separate operations by separate groups. OpSouthAfrica was politically motivated data claims by a hacktivist group. The BlackMatter DDoS campaign was financial extortion through service disruption targeting hosting providers. Different actors, different motives, and different attack types.

Sources

Are your credentials already in circulation?

Ubuntu Guard's credential exposure audit searches public breach indexes and dark-web infostealer markets for your organisation's email domains. You get a full exposure inventory and a rotation priority list.

Book a Credential Exposure Audit

Questions? Reach us at [email protected]