Defend Truth

GROUNDUP

Postbank loses over R18-million to cybercrime attacks in three months

Postbank loses over R18-million to cybercrime attacks in three months
Postbank says it will spend R400-million to upgrade its IT systems to counter similar attacks. (Archive photo: Supplied by Sassa)

Most of the money stolen came from the Sassa beneficiary grant payment system, says CEO.

The South African Postbank is to spend R400-million over the next three years to upgrade and modernise its IT systems.

This follows the state-owned entity losing more than R18-million over a three-month period to cybercrime attacks.

On Tuesday, Postbank CEO Lucas Ndala told Parliament’s portfolio committee on communications that it had “a number of cyber fraud incidents — most of them relating to the Sassa beneficiary grant payment system”.

Ndala said the Postbank IT system had been flagged by the Auditor General for having “control weaknesses”.

“There has been a concerted effort to address these system deficiencies since the grant system was ceded to Postbank in 2021. A lot of these weaknesses come from the system itself because it came with a number of flaws that needed to be addressed over time,” Ndala said.

In response to DA MP Dianne Kohler Barnard on the total cost of the IT update, Ndala said, “The total cost approved is just around R400-million. This will be funded from Postbank resources. The modernisation will be over a three-year period.”

He said the accounts of 141 grant beneficiaries were hit in a cyber attack in August. The state-owned entity lost R5.8-million in this incident.

The second incident happened in September, also involving accounts receiving social grants on behalf of children. Ndala said the Postbank’s Fraud Risk Team discovered that some of these accounts were fraudulent, and, as a preventative measure, these were blocked.


Visit Daily Maverick’s home page for more news, analysis and investigations


However, “the blocking was not done properly,” said Ndala. “Anyone could unblock them within our branch network,” he said. Postbank lost about R4-million in this incident.

In October 2022, Ndala said the Postbank banking system suffered another cybercrime attack and lost about R9-million.

Earlier this year it was revealed that the Postbank had suffered a loss of at least R90-million in cybercrime attacks in October 2021.

Ndala told MPs that Postbank is on the same IT network as the South African Post Office (Sapo). One of the requirements when Postbank applied for a banking licence from the SA Reserve Bank, was that it needed its own “stand-alone IT environment that cannot be impacted by the risks from Sapo”.

Ndala said the report on a forensic audit into the recent cybercrime incidents is expected to be released in December, while the second part of the report is expected in February 2023.

Nonkqubela Jordan-Dyani, acting Director-General in the Department of Communications and Digital Technology, said: “There needs to be consequence management because these are public funds and funds that belong to Postbank. We need to make sure that all those responsible are held accountable.

“The Hawks will guide us in their process, and from our side, we are intending that the report will be tabled to the Cabinet,” said Jordan-Dyani.

Postbank did not respond to questions on whether payments to social grant beneficiaries were affected or how it had covered the losses. DM

First published by GroundUp.

Gallery

Comments - Please in order to comment.

  • Jane Crankshaw says:

    Wouldn’t expect anything less than this theft! Once Net 1 who used to successfully pay Social Grants was suspended and “the powers that be” took over, it was just a matter of time before taxpayers money was once again stolen! I very much doubt it’s only R18m….that’s just to soften us up for the reality!

Please peer review 3 community comments before your comment can be posted

X

This article is free to read.

Sign up for free or sign in to continue reading.

Unlike our competitors, we don’t force you to pay to read the news but we do need your email address to make your experience better.


Nearly there! Create a password to finish signing up with us:

Please enter your password or get a sign in link if you’ve forgotten

Open Sesame! Thanks for signing up.

We would like our readers to start paying for Daily Maverick...

…but we are not going to force you to. Over 10 million users come to us each month for the news. We have not put it behind a paywall because the truth should not be a luxury.

Instead we ask our readers who can afford to contribute, even a small amount each month, to do so.

If you appreciate it and want to see us keep going then please consider contributing whatever you can.

Support Daily Maverick→
Payment options

Premier Debate: Gauten Edition Banner

Gauteng! Brace yourselves for The Premier Debate!

How will elected officials deal with Gauteng’s myriad problems of crime, unemployment, water supply, infrastructure collapse and potentially working in a coalition?

Come find out at the inaugural Daily Maverick Debate where Stephen Grootes will hold no punches in putting the hard questions to Gauteng’s premier candidates, on 9 May 2024 at The Forum at The Campus, Bryanston.