South Africa's cops got hacked. Here's what was stolen.

By Ubuntu Guard Cyber | 6 May 2026

South Africa's cops got hacked. Here's what was taken, and what it means.

In March 2026, a group called ShinyHunters broke into Polmed, the Police Medical Aid Scheme, and walked out with health records, home addresses, financial details, and job titles belonging to members of the South African Police Service. Sensitive doesn't cover it.

They didn't leak it to the press. They emailed Polmed directly. One million US dollars in seven days, or everything goes public.

What got taken

This was not a generic data dump. Cybersec Clinique, the firm brought in to investigate, was clear about why it matters: the stolen data doesn't just expose individuals. It maps out parts of the SAPS command structure.

ID numbers. Home addresses. Specific police roles. Put those three things together and you've handed criminals a targeting list. Undercover officers, senior detectives working organised crime, high-ranking officials, their identities and locations may now be in the wrong hands. Not in some vague place, but rather in a searchable list.

Cybersec Clinique called it "a critical risk to national security and personnel safety." That's the finding of the people who examined the data and not a press release.

How they got in

ShinyHunters did not brute their way in. According to investigators, they exploited a weakness in Polmed's architecture that let them forge digital credentials, impersonating legitimate administrators until they had the access they needed. Nothing triggered. To the system, they looked like they were supposed to be there.

The breach ran undetected long enough to pull substantial data. Polmed found out when ShinyHunters told them.

Who ShinyHunters are

This is not a single person or lone threat actor. ShinyHunters has hit Ticketmaster, Salesforce, and Snowflake. They've been active for six years. The model is simple: get in, take data, demand payment, publish if you don't get it.

South Africa isn't a random target either. It fits a pattern. Public institutions, complex vendor chains, and uneven security across third-party administrators make for a predictable combination.

What happens now

Polmed has notified the Information Regulator, SAPS, and the Council for Medical Schemes. Multiple investigations are running. Whether the breach started inside Polmed's own systems or through a third-party administrator is still unclear. That question matters under POPIA, and it determines who carries the liability.

The data is out. Breaches like this don't stop being damaging when the investigation starts. Identity fraud, social engineering, targeted intimidation, these tend to surface months after the initial incident, when everyone has moved on.

For the officers whose information is now circulating, the threat is ongoing.

Reach us at [email protected] if you want a second pair of eyes on your organisation's exposure.

Want to know what an attacker can already see about your organisation?

Run a free Business Trust Check to see what an attacker can already see about your domain, email, and exposed services. No signup, under two minutes.

Run a Free Business Check

Sources:

Questions? Contact us at [email protected]

← Back to Blog