1. Executive summary
Between 17 and 25 May 2026, a Nigerian hacktivist crew calling itself Nullsec Nigeria, along with three other handles named in subsequent reporting (404 Crew, Infernalis, and Nullsec Philippines), ran a coordinated visibility campaign under the hashtag #OpSouthAfrica. The crew claimed compromises against nine South African public-sector targets, including SARS, SITA, the Department of Correctional Services, SACAA, SANSA, SASSA, the Department of Human Settlements, the National Housing Finance Corporation, and Ephraim Mogale Local Municipality.
SARS and SITA publicly refuted the breach claims on 25 May 2026. Independent threat researchers reading the published file structures suggested the payload may represent an aggregation of historically recycled credential dumps or third-party infostealer logs, repackaged to maximise geopolitical visibility rather than fresh intrusion data.
The honest reading is hacktivism oriented at attention, not extortion. The campaign should be treated by South African organisations as a prompt to harden third-party exposure and credential hygiene, not as a confirmed government compromise event. This report walks through the full investigation, target by target, with evidence quality ratings for each claim.
2. Why this case study exists
Most South African coverage of cyber incidents focuses on the claim. A hashtag goes viral, a journalist publishes the claim, the public reads the claim, and the affected organisation either denies or stays silent. By the time forensic facts emerge, the news cycle has moved on. The result is a public that does not know which claims to trust and a business community that does not know how to respond proportionately.
This case study reflects Ubuntu Guard's approach to cyber intelligence. We focus on the data, not the marketing. We rate claims by evidence quality. We separate hacktivism from extortion. We disambiguate concurrent campaigns. We publish our methodology alongside our conclusions, so the reader can judge our analysis on its terms rather than on our authority.
If you sit on a board, run a security programme, or sign off on POPIA notifications, this case study gives you the structure to push back on the next breach claim without overreacting.
3. The actors
Nullsec Nigeria
Nullsec Nigeria (also known as Anonymous Nigeria) first surfaced in its current branding around April 2026. Earlier "Anonymous Nigeria" activity dates further back. The crew claimed the EFCC (Economic and Financial Crimes Commission of Nigeria) leak on 21 April 2026, posting on a dark-web forum called Breached. The operator alias most prominently named in Nigerian press coverage is ki4t. Distribution channels include a branded Telegram channel, the Breached forum, and amplification through X (formerly Twitter) and the Zimbabwean publication TechnoMag's Facebook page.
The crew's stated motivation for OpSouthAfrica was retaliation for xenophobic attacks against Nigerians in South Africa. The group's quote, reproduced by MyBroadband: "Unless the government of South Africa ends these xenophobic attacks on Nigeria, we'll expose everything about you."
Observed motivation is mixed. The group targeted its own government (EFCC, CAC) a month before launching OpSouthAfrica, undermining a pure pan-African nationalist framing. The crew appears opportunistic, with political framing layered on top of broader anti-government activity.
404 Crew
404 Crew was first named in #OpSouthAfrica coverage by Daily Maverick's Lindsey Schutters on 18 May 2026. Schutters himself caveated: "not sure if it is the same 404 Crew that disrupted service delivery in IoT/smart city hacks in the US." The identity remains ambiguous.
Infernalis
Infernalis was first named in the same Daily Maverick piece. No prior reporting or documented forum presence has surfaced for this handle in the SA hacktivism context. Unable to verify as a distinct actor.
Nullsec Philippines
Nullsec Philippines was first named on 25 May 2026 by Brinztech, a Dubai-based threat intelligence monitor, and named as a joint actor on the SARS-SITA claim. Status: unverified as a distinct entity.
4. Campaign timeline
| Date | Event | Source |
|---|---|---|
| 11 May 2026 | President Ramaphosa publishes newsletter condemning xenophobic violence | presidency.gov.za |
| 17 May 2026 | MyBroadband publishes first report on Nullsec claim against DCS and Ephraim Mogale Local Municipality | mybroadband.co.za |
| 17 May 2026 | Dark Web Informer X account confirms Ephraim Mogale claim was posted (confirmation of posting, not validity) | x.com/DarkWebInformer |
| 18 May 2026 | Daily Maverick expands target list to include SACAA, SANSA, SASSA, Department of Human Settlements, NHFC. Names 404 Crew and Infernalis as additional actors | dailymaverick.co.za |
| 19 May 2026 | Separate concurrent campaign: DDoS attacks hit SA hosting providers (1-Grid, Xneelo, Network Platforms, Seacom). Group claims to be "BlackMatter" — distinct from Nullsec | TechCentral, ITWeb |
| 23 May 2026 | MyBroadband follow-up: Nullsec claims SARS and SITA breach | mybroadband.co.za |
| 24 May 2026 | Brinztech publishes threat alert on SARS-SITA claim, naming Nullsec Philippines as joint actor | brinztech.com |
| 25 May 2026 | SITA issues public refutation via Tlali Tlali (head of corporate affairs) | ITWeb, TechCentral |
| 25 May 2026 | SARS issues public refutation, calling claims "false and unsubstantiated" | ITWeb, TechCentral, BusinessTech |
| 30 May 2026 | Ubuntu Guard publishes full investigation (this report) | ubuntuguard.co.za |
5. Target-by-target analysis
The table below summarises each claimed target, the nature of the claim, the organisation's public response, a technical assessment of the evidence, and an evidence quality rating based on the available public record. Evidence quality ratings are assigned as Disputed where the target has formally and specifically refuted the claim with supporting technical detail, and as Unverified where no sample data or independent forensic confirmation exists in the public record.
| Target | Claim | Response | Technical assessment | Evidence quality |
|---|---|---|---|---|
| SARS (South African Revenue Service) |
Database archive containing names, email addresses, and passwords from eFiling platform users. Distributed for free on Breached forum, 23–25 May 2026. | SARS (25 May 2026): "These claims are false and unsubstantiated. SARS continuously monitors its systems for any suspicious activity and has conducted a thorough investigation. There is no evidence that SARS's systems have been compromised." | Dump claims cleartext passwords. Modern login systems store hashes, not original passwords. Cleartext credentials are consistent with infostealer logs harvested at user endpoints or older third-party breaches — not a direct SARS database compromise. Brinztech (25 May): payload "may represent an aggregation of historically recycled credential dumps or third-party infostealer malware logs repackaged to maximize geopolitical visibility." | Disputed |
| SITA (State Information Technology Agency) |
Link containing names, passwords, and platforms used to access SITA services. Distributed for free on Breached forum, 23–25 May 2026. | SITA (24–25 May 2026): "Our ICT infrastructure remains fully intact and has not been compromised. There is no evidence of any unauthorised access to government data or systems. We run a multi-tiered scan of our security environment and are satisfied that there are grounds to refute these claims." One department website acknowledged as under planned maintenance — described as scheduled work, not attack-related. | Same technical and structural issues as the SARS claim. SITA's denial is unusually detailed (multi-tiered scan, named spokesperson, 24/7 SOC reference) compared with how SA government agencies have typically responded to confirmed breaches, which lends weight to the denial. | Disputed |
| DCS (Department of Correctional Services) |
Sample of bid invitation notices, bid results, bids received, award notices, a public hearing image, a handwritten tender document for an insurance service provider, an old annual report, council resolutions, financial statements, and various notices. Group claimed total volume of approximately 11 GB. | No statement issued. DCS news feed shows no breach statement at time of publication. | Substantial portions of the sample category are legally required to be published on departmental websites and the government tender bulletin. A sample of bid notices does not by itself prove internal compromise. The handwritten tender document is the most notable item: handwritten tenders are not typically published proactively. Their presence suggests either internal access or a misconfigured upload directory — the latter is the more common finding in portal audits. | Unverified |
| Ephraim Mogale Local Municipality | Group quoted: "we'll expose everything you got for others to see how heartless you are." Sample data type not described beyond an assertion that the website was hacked. | None observed. Municipal website operational. No press statement. | Dark Web Informer X account independently confirmed the claim was posted — not its validity. Smaller local municipalities have weaker public-disclosure track records, so the absence of a denial is a weaker signal than for SARS. Without sample-data inspection, the claim cannot be confirmed or refuted. | Unverified |
| SACAA (South African Civil Aviation Authority) |
Listed in Daily Maverick's 18 May aggregation as a target. No sample data published in the public record at time of publication. | No public statement specific to the Nullsec claim. | Listed without sample evidence. No forensic basis to confirm or refute in the public record. | Unverified |
| SANSA (South African National Space Agency) |
Listed in Daily Maverick's 18 May aggregation as a target. No sample data published in the public record at time of publication. | No public statement specific to the Nullsec claim. | SANSA has a strong prior disclosure track record on confirmed incidents (2021 CoomingProject/GhostSec claim; September 2025 staff email compromise). Current silence is a mild signal that the agency does not consider the present claim valid. | Unverified |
| SASSA (South African Social Security Agency) |
Listed in Daily Maverick's 18 May aggregation as a target. No sample data published in the public record at time of publication. | No public statement specific to the Nullsec claim. | Listed without sample evidence. No forensic basis to confirm or refute in the public record. | Unverified |
| Department of Human Settlements | Listed in Daily Maverick's 18 May aggregation as a target. No sample data published in the public record at time of publication. | No public statement specific to the Nullsec claim. | Listed without sample evidence. No forensic basis to confirm or refute in the public record. | Unverified |
| NHFC (National Housing Finance Corporation) |
Listed in Daily Maverick's 18 May aggregation as a target. No sample data published in the public record at time of publication. | No public statement specific to the Nullsec claim. | Listed without sample evidence. No forensic basis to confirm or refute in the public record. | Unverified |
6. Why this matters for South African organisations
Three structural lessons travel from this campaign to every SA organisation, regardless of whether the individual claims are confirmed.
Credential exposure is the real threat, not the government breach claim. Whether or not the Nullsec SARS dump came from inside SARS, the credentials in it are real. They were harvested from real people on real laptops, and they still work for whoever holds them. If any of your staff or supplier email addresses appear in stealer logs, the operational risk is the same regardless of the originating claim.
Tender and supplier portal exposure is the soft target. The DCS sample data was largely public-record tender material. The credible attacker workflow is to crawl every public URL, walk sequential IDs, query the API endpoints, and bundle whatever comes back. Most SA government and parastatal portals have access controls enforced at the user interface layer but not at the API layer. This is the dominant pattern in SA public-sector IT exposure.
POPIA compliance posture matters more than ever. The Information Regulator's enforcement trajectory through 2024 and 2025 has been toward enforcing notification timing, not just substantive compliance. SARS and SITA's same-day named-spokesperson denials reflect this awareness. SA organisations that have not registered an information officer, drafted breach notification templates, or run a tabletop exercise are exposed to fines independent of any technical compromise.
7. Recommendations
The following recommendations are calibrated to the realistic threat surface this campaign reveals: hacktivism, opportunistic public-facing exploitation, credential aggregation, and public visibility plays. They are not written for nation-state TTPs.
- Public-facing web-application hardening. Hacktivist campaigns favour low-effort, high-visibility entry points. Review every public-facing portal: outdated CMSes, exposed admin interfaces, weak authentication on staff dashboards, and file upload paths without server-side validation.
- Credential hygiene at the user layer. The most defensible reading of the Nullsec data is aggregation from infostealer logs harvested off endpoints. Force password resets on any account where the email domain appears in publicly indexed infostealer dumps. Mandate phishing-resistant MFA on every administrative interface.
- Tender and procurement portal audit. Review what your portal exposes to unauthenticated visitors versus authenticated supplier accounts. Confirm that separation is enforced at the access-control layer, not just the UI layer.
- Leak monitoring with a clear escalation path. Continuous monitoring against your own domains on Breached/BreachForums, Telegram channels, and X. Pre-decide who confirms facts internally, who contacts the Information Regulator, and who briefs the public.
- POPIA-aware communication posture. Have a draft notification template ready and a legal review path agreed in advance. Do not wait until a claim is confirmed to prepare the response.
- Patch the recycled-credential risk specifically. Even if the Nullsec claims are recycled, those credentials are still live for any account where the user has not rotated their password since the original harvest.
- Coordinated public statement on policy. Clear, named-spokesperson denial, no defensive over-explaining, pointing readers to official channels. Practice this before you need it.
8. About Ubuntu Guard
Ubuntu Guard is a South African cybersecurity consultancy serving small and medium businesses across KZN, Gauteng, and the Western Cape. We provide credential exposure audits, public portal hardening reviews, POPIA dry-run exercises, and monthly threat intelligence briefings.
This case study and its source materials are published under TLP:CLEAR classification. The full source list (40+ primary references) is available on request from [email protected].
Concerned about your organisation's exposure?
Ubuntu Guard runs credential exposure audits, portal hardening reviews, and POPIA dry-run exercises for SA organisations. Get a prioritised finding list with reproduction steps.
Request a security assessmentQuestions? Reach us at [email protected]