The Department of Social Development (DSD) concluded phase one of its investigation into potential fraud in the Social Relief of Distress (SRD) grant online system.
Last year, two first-year computer science Stellenbosch University students discovered severe bugs and fraud in the South African Social Security Agency’s (Sassa) SRD grant system.
After conducting legal vulnerability tests, the pair of students found alarmingly high application rates for individuals born in 2005, suggesting mass fraudulent activity, and the approval of fraudulent applications using their ID numbers, while legitimate beneficiaries were denied.
A campus survey further highlighted the scale of the problem, revealing that many students had fraudulent applications filed in their names without their knowledge.
The significant media coverage received by the students prompted an investigation into the vulnerabilities of the SRD grant payment system.
Social Development Minister, Sisisi Tolashe says the audit results will be used to inform the second phase. This second phase will be a deeper investigation into potential fraud and systemic flaws across the entire social grant programme, specifically focusing on how ineligible individuals are receiving benefits.
Phase One Findings
A report on the vulnerability assessment and penetration testing of the SRD grant online system has revealed critical security weaknesses which potentially expose vulnerable applicants to fraud.
The audit uncovered the existence of numerous unidentified, malicious websites, using seemingly legitimate ".org" and ".co.za" domain names.
These sites deliberately mimic the authentic SRD application platform potentially deceiving grant beneficiaries into providing their personal information. Alleged fraudsters could then use this information to access grant payments meant for vulnerable individuals.
Security Improvement Measures
Sassa will implement a comprehensive action plan to improve its systems to protect grant beneficiaries and their information. This includes implementing data protection protocols, introducing enhanced biometric verification checks, regularly updating its systems and removing fraudulent websites.
A core component of this plan involves enhancing data protection by transitioning to the "POST" method for online data transmission, replacing previous protocols and providing a more secure channel for applicant information.
Sassa will also implement "rate limits," which will restrict the number of online requests allowed within a given timeframe, effectively blocking automated attacks and excessive traffic.
The agency has committed to regular software updates and security patches which they believe will close potential loopholes and strengthen defences against cyber threats.
Sassa also plans to introduce biometric verification mechanisms to make it harder for fraudsters to impersonate legitimate beneficiaries.
The agency will commit to a long-term initiative to take down fraudulent websites and online content.







