Facebook tracking pixel

Stats SA Data Breach Puts Job Seekers at Risk as Agency Refuses R1.7 Million Ransom

Stats SA data breach
Generated Image: Copyright Newcastillian News

Statistics South Africa has confirmed a cybersecurity breach involving one of its primary human resources databases, where an emerging cyber-extortion group is now demanding a $100,000 (R1.7 million) ransom to prevent the public release of stolen data.

This cache reportedly includes the sensitive personal information of hundreds of thousands of job seekers.

Pixelfish Marketing
Advertising

The group, calling itself XP95, claimed responsibility via Telegram and its dark web leak site, asserting that it successfully exfiltrated 453,362 files totalling 154GB from a Stats SA server. The hackers have issued a deadline of 20 April 2026 for payment; should this demand remain unmet, they threaten to release the full archive online.

In response, Stats SA has maintained a firm position, stating that it has no intention of paying the $100,000 (R1.7 million) ransom.

Notably, this incident marks the second major government breach attributed to XP95 in March 2026, following its earlier claim against the Gauteng Provincial Government.

Nevertheless, Semakaleng Thulare, Acting DDG for Statistical Support and Informatics, confirmed that the organisation is aware of the breach affecting the recruitment-specific database.

“The system that was breached is exclusively the HR system available for job seekers to apply online,” said Thulare.

She added that the national statistics office is currently part of a wider government response to cybersecurity breaches and will notify the Information Regulator to be guided by its formal processes.

The breach raises significant concerns regarding the potential for identity theft and data misuse, particularly as many applicants access the e-recruitment portal from shared facilities or personal devices that may lack adequate protection.

In an interview with SABC News, Statistician-General and Head of Stats SA, Risenga Maluleke, explained that the compromise likely occurred through the very platforms users rely on, such as internet cafés or insufficiently protected phones. Consequently, it is primarily the applicants’ own information that now stands at risk.

Thulare reinforced this position in comments to MyBroadband, making clear that Stats SA will not pay any ransom because the deployment of state financial resources must comply with the Public Finance Management Act (PFMA).

This legislation strictly governs the transparent and accountable use of public funds, effectively prohibiting such payments.

Furthermore, Stats SA has stressed that the incident was confined to the job application portal and did not compromise its core statistical systems. These systems continue to hold sensitive national data, including census records, economic indicators, and demographic information.

Officials remain in collaboration with the relevant authorities to manage the situation and support those potentially affected by the exposure.

As the 20 April 2026 deadline approaches, the situation remains a critical test of the South African government’s resolve against escalating cyber-extortion tactics.

AME Amajuba
PAID ADVERTISING

Moving forward, the incident underscores an urgent necessity for Stats SA and broader state organs to fortify the security of public-facing portals.

What are your thoughts on this? Let us know below.

Be sure read:

Newcastillian News invites your input. We ask that you keep your remarks courteous and on-topic. We do not allow any form of hate speech, such as racist or sexist comments. All comments are subject to moderation in line with our User Rules and Commenting Policy.

SPONSORED

Advertise your business to South African readers.

Follow us on WhatsApp

Get the latest local news and breaking updates straight to your phone.

CATEGORIES