OpSouthAfrica: a hack that probably was not, and why your business should still pay attention

By Ubuntu Guard | 26 May 2026

Last week a Nigerian crew calling itself Nullsec Nigeria posted to a dark-web forum, named seven South African government bodies, and said it had hacked all of them. The hashtag was #OpSouthAfrica. The framing was political: stop the xenophobic violence against Nigerians in South Africa, or we expose everything.

SARS and SITA pushed back the same week. SARS said the claim was "false and unsubstantiated." SITA said its infrastructure was "fully intact" and pointed to a multi-tiered scan that found no anomalies. Independent threat researchers reading the leaked files said something more useful: the data looks like recycled credentials and infostealer malware logs, dressed up to ride the news cycle.

We run a cybersecurity firm in South Africa. We read every line of public reporting on this campaign, plus the file-shape commentary from the monitors who opened the dumps. The honest read is that the hack mostly did not happen the way Nullsec said it did. The story behind the story is what your business needs to understand, because that one is real, and it affects you.

What was claimed

Between 17 and 25 May 2026, Nullsec Nigeria, along with two other handles named in the same coverage (404 Crew and Infernalis, and later a fourth called Nullsec Philippines), claimed compromises against the following organisations:

Nine targets in eight days. No ransom was demanded, files were dumped free on a hacker forum called Breached, and posts were amplified on Telegram and X, with TechnoMag and Daily Maverick picking up the story.

If a crew breaches nine government agencies in eight days, two things should follow: forensic confirmation from at least one of them, or operational disruption visible from the outside. Neither happened. Government portals stayed up. No insider data has surfaced that could not have come from somewhere else. SARS and SITA went on record to refute the claims, and the rest mostly stayed quiet.

What probably happened

The SARS claim is the easiest to examine. Nullsec said the dump contains usernames, email addresses, and cleartext passwords for SARS eFiling users. That is the technical tell. Any production-grade login system, especially one operated by a national tax authority, stores password hashes rather than the passwords themselves. A hash is a one-way fingerprint. You can check whether the password you typed matches the hash on file, but you cannot read the password out of the hash.

When a dump contains cleartext passwords, the most likely sources are not the company whose login page they belong to. They are:

  1. Infostealer malware sitting on the user's own laptop. Strains like Redline, Lumma, StealC, Vidar, and Atomic harvest credentials at the moment the user types them into a browser, before any encryption or hashing happens. Those credentials then get bundled and traded by the thousand on the same forums Nullsec posts to.
  2. Older breaches from third parties that stored passwords poorly, combined with people reusing the same password across services.
  3. Phishing kits that impersonate a login page and grab credentials at the fake door.

All three paths produce data that looks identical to a "we hacked SARS" dump. None of them require touching SARS. The independent monitor Brinztech, reviewing the file structure, said the consensus among researchers is that the payload is "an aggregation of historically recycled credential dumps or third-party infostealer malware logs repackaged to maximise geopolitical visibility." The simpler reading: the hackers took material that was already in circulation, labelled it SARS, and posted it under a hashtag.

The Department of Correctional Services sample is its own kind of thin. The published material consisted of tender invitations, bid results, an old annual report, council resolutions, and financial statements: almost all of it the kind of document government departments are legally required to publish anyway, available on departmental websites and the government tender bulletin. Posting routine public-record material is not proof of a deep intrusion. It is proof that the group can use Google.

This pattern repeats. The same Nullsec persona, posting as "ki4t", made an equivalent claim against Nigeria's own Economic and Financial Crimes Commission in April. Over a month later, there was no confirmation, no operational impact, and no forensic evidence. Loud claim, thin data, no follow-through.

Why the underlying credential risk is real

The reason recycled credential dumps are dangerous is that the credentials in them still work. The reason infostealer logs are dangerous is that they are harvested from real people, on real laptops, who use the same password across their personal Gmail, their work portal, their banking app, and their accounting software.

If your staff's work email appears in one of these dumps, an attacker does not care whether the original claim was a SARS breach or not. They will try the credential against your Office 365 tenant, your Xero account, your AWS console, your CRM. If it works, you have a problem that started long before any hashtag campaign and has nothing to do with hacktivism.

This is the silent breach economy, running quietly in the background of every news cycle for years. The Nullsec story is loud and probably mostly fabricated. The infostealer story is quiet and almost certainly involves people you employ.

What this means for South African SMEs

Stop treating breach claims like binary events. A claim is not a confirmation. A refutation is not an all-clear. The right response sits in between: assume credentials may be exposed, check, rotate where needed, and watch what happens next. Panic and complacency are both expensive.

Find out whether your people are in the dumps. Domain-level monitoring with services like Have I Been Pwned will tell you whether any account on your work domain has appeared in a publicly indexed breach. There are commercial services that go further and search infostealer logs specifically. This is the single highest-yield exercise an SME can run.

Get phishing-resistant MFA on every administrative interface. SMS codes are better than nothing but can be intercepted via SIM swap, and SIM swaps are not rare in South Africa. Use an authenticator app (TOTP) or a hardware key. Anywhere a password unlocks money, customer data, or the ability to send email as your business, MFA is the rule.

Audit what your public portals expose. The Correctional Services sample was procurement material. Some of it should be public; some should not. Most departments and most SMEs have never had anyone verify whether the line between the two is enforced at the access-control layer rather than just at the user interface. Those are very different things.

Have a draft breach notification ready before you need it. Under POPIA's Section 22, the responsible party must notify the Information Regulator and affected data subjects when there are "reasonable grounds to believe" personal information has been accessed without authority. The threshold is informed suspicion, not forensic certainty. Drafting that notification under pressure is a poor time to start from a blank document.

Know the difference between hacktivism and extortion. Nullsec wants attention. The DDoS wave that hit South African hosting providers around the same time, claimed by a group calling itself BlackMatter, wants money. These are different threats requiring different responses.

What the Nullsec campaign reveals

An opportunistic crew with a Telegram channel and an editing tool convinced a meaningful portion of the South African public that nine government agencies were hacked, when most of them probably were not. That trick works because the underlying anxiety is justified. Standard Bank disclosed a breach in April. Stats SA was hit with a real ransom demand. Gauteng disclosed a 3.8TB data exposure earlier in the year. There is enough genuine breach activity in the country that a manufactured story slots in believably.

Your customers, suppliers, board, and team have all learned that breach claims happen weekly, and most of them cannot tell the difference between a Brinztech analysis and a forum post. Filling that gap, calmly and competently, is the security work most South African businesses still need to do.

Where Ubuntu Guard fits

We completed the full investigation this article summarises. We mapped every claim to its evidence, rated every target by confidence, cross-referenced the South African and Nigerian primary sources, and consulted the independent monitors who examined the file trees. We did not visit the hacker forums or open the leaked files. The story was already on the public record; it needed someone to read all of it.

If you want the full investigation — with the timeline, the target table, the IOCs, and the defensive playbook — it is available as a TLP:CLEAR threat brief on request. If you want a credential exposure check against your own domain, or a hardening review of your public-facing portals, that is what we do.

The Nullsec campaign will fade from the news. The infostealer dumps it was assembled from will not. The work is in the second category.

Sources

  • MyBroadband: "Nullsec Nigeria hacks South African government" (Published: 17 May 2026)
  • MyBroadband: SARS and SITA claims follow-up coverage (Published: 23–25 May 2026)
  • Daily Maverick (Lindsey Schutters): OpSouthAfrica campaign analysis (Published: 18 May 2026)
  • Brinztech: Threat alert — OpSouthAfrica credential dump analysis (Published: 25 May 2026)
  • SARS: Public refutation statement — eFiling breach claim (Published: 25 May 2026)
  • SITA / Tlali Tlali: Infrastructure integrity statement (Published: 25 May 2026)

© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Find out which of your accounts are in the dumps

Ubuntu Guard runs credential exposure audits across public breach indexes, dark-web brokers, and infostealer log markets. The output is a ranked list of which accounts to rotate and which to monitor ongoing.

Get a Credential Exposure Audit

Questions? Reach us at [email protected]