Last week the Companies & Intellectual Property Commission (CIPC) announced that it had fallen victim to a cyber attack that has compromised the personal information of both its clients and employees.
The CIPC is an agency under the department of trade, industry & competition, and thus falls under minister Ebrahim Patel. It is responsible for registering companies, intellectual property rights (patents, trademarks) and the like.
It sits on a treasure trove of information — personal identities, contact details, financial and banking info, BEE applications and certifications, and more. If I was a would-be hacker with privacy pirate mindset it would be near the top of my watch list (at least locally) — an inherent risk so obvious that one would hope the commission would have been cyber-secured to the teeth.
This hope has been soundly dashed, despite the assurances in the CIPC’s disclosure statement — a legal requirement stemming from section 22 of the Protection of Personal Information Act (Popia). That announcement went up on its website, cipc.co.za, last Thursday.
While it probably ticks the Popia box for compliance — if not, I’m sure the legal eagles will soon let us know — I believe it fumbles from the first sentence: “You are hereby notified that the CIPC noted an attempted security breach and the compromise of personal information of clients and CIPC employees, held on the CIPC records.”
“Attempted” seems a strange choice of word for a breach the CIPC acknowledges happened. And it minimised again in the following sentence: “Our ICT technicians were alerted, due to extensive firewall and data protection systems in place at the CIPC, to a possible security compromise.”
Hmm. “Possible” compromise? And yet right there, in black and white, is the confirmation that “certain personal information of our clients and CIPC employees was unlawfully accessed and exposed”. It’s just a notice, sure, but it doesn’t telegraph transparency.
There is another set of actors in the mix who allege the linguistic minimisation deployed here is the least of our concerns. A group claiming to be the ransomware gang responsible contacted tech news website MyBroadband after the CIPC published its notice, declaring the commission’s assertion that it detected and contained the breach through its own systems to be “completely false”.
No action
Instead, the group alleges it has “had access to the agency’s systems since 2021”, and that the CIPC has known about the breach for years and done “nothing to address its weak security”, MyBroadband writes.
The group provided journalist Jan Vermeulen with a stack of evidence that it says proves its case that the agency is lying, and allege it found unencrypted passwords and credit card information and could have exfiltrated the CIPC’s whole database and even changed company director details. The original reporting here is well worth a gander, but boils down to the suggestion that not only was the hack anything but attempted, but the site remains vulnerable.
The CIPC has not commented further, to Vermeulen or any of the other journalists now covering the story, as far as I can find. On Tuesday it did publish an additional update though, regarding a new customer verification process as part of its efforts to secure customer accounts.
The referenced documents can be found under “important notices” on the landing page of the site, but all told the information provided is scant on detail and I have found no further mentions warning customers, on their social media for instance, which are regularly updated and prominently promoted.
I want to give the CIPC the benefit of the doubt, and I don’t have sight of the inner workings of its systems, but I would argue that an abundance of caution, and “over-communicating” would be a better strategy, even if it does have things squarely in hand.
The apparent transparency mismatch is not a good look. One side is actual cybercriminals keen to share the details, processes and proofs of what they did, and the other a public institution looking tight-lipped about the whole palaver. Exploring their relative motives complicates the narrative a little; the cyberbaddies are certainly incentivised to exaggerate.
The CIPC has worked hard over many years to earn a reputation as a rare public entity that can be trusted to do its thing. We’re geared up to give them even more information to manage, in the form of the beneficial ownership filings. This breach and the handling of the information (so far) is a sharp blow to that perception. I am sorry this misfortune has prompted a diatribe on the government’s digital sophistication, or lack thereof, but here it is.
It is time to demand more of our public bodies. Yes, in all the other ways you’re thinking of, but I am speaking digitally now. Ten or 15 years ago our glitchy government websites, and the wonky ICT infrastructure they often contain, was kind of embarrassingly funny. Dead links, grammar crimes on their web pages and outdated, clunky design, is just the kind of thing that speaks to our collective laugh-through-the-pain national identity.
But in 2024, as public entities around the world start to deploy smart chatbots and intuitive self-service systems, as mobile portals — rather than administrative buildings and their perpetually “offline” desk jockeys — become our default means to accessing support, I am no longer laughing.
We’re not after slick, but functional. No-one needs to fork out millions in tenders to put together a website or database that reflects that it has been built by professionals who take their duty of care seriously, whether they are tasked with safeguarding resident and citizen data, or “simply” sharing information with the people they are supposed to serve.
• Thompson Davy, a freelance journalist, is an impactAFRICA fellow and WanaData member.













Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.
Please read our Comment Policy before commenting.