We discovered massive fraud in SASSA’s grant system
Thousands of grants were being claimed against the ID numbers of people who never applied. The findings went to Parliament.
Then I write them up. Computer science student at Stellenbosch, security and fraud analyst at Capitec, developer and columnist at GroundUp News. Sixteen bylines, four government departments, one grant system that shouldn’t have been that easy to break.
Red, blue and purple team work at Capitec: internal penetration testing, endpoint breakout, lateral movement, API testing with Burp Suite and Postman. Two critical internal vulnerabilities found and reported.
Columnist at GroundUp News on fraud, data breaches, RICA compliance and the state of government IT. The SASSA SRD work drew national attention and engagement with Parliament.
Django, Python, Linux, Nginx, Cloudflare, Azure, Microsoft 365 and Google Workspace. Newsroom features shipped, whole organisations migrated, one DoS attack traced back to its source.
Thousands of grants were being claimed against the ID numbers of people who never applied. The findings went to Parliament.
Part one of a four-part series with Nathan Geffen on the security and usability of government’s websites. SITA’s internet services carried more than 5,000 security flaws.
Social media influencers helped make the scam possible, and were rewarded handsomely. The series went on to trace the police credibility and the money mules behind it.
Conferences, panels, campus talks, podcasts and broadcast interviews on grant fraud, scam syndicates and the state of government IT.
Websites, hosting, security reviews, cloud and workspace migrations for small businesses and nonprofits. Since 2023.
Tip-offs, disclosure, hiring, or a website that needs building. Email is the fastest way in.