Brothers uncover vulnerabilities in NSFAS student data system

Two information-technology-savvy brothers have discovered serious flaws in the National Student Financial Aid Scheme's ICT system, potentially exposing millions of students' personal details, including bank accounts, to scammers. The vulnerabilities allowed access to sensitive messages, one-time pins, and even administrative functions like altering funding. NSFAS has since patched the most critical issues after being alerted.

Connor Bettridge, a computer science student at Varsity College in Cape Town, stumbled upon the issues while assisting with an NSFAS funding application. He accessed the portal's communication page and viewed students' addresses, gender, income, and bank details. His older brother, Jordan Bettridge, who works in insurance technology, investigated further.

Jordan described how the system allowed anyone to access all SMSes and emails sent by NSFAS since 2022, including one-time pins and personal information for between half a million and a million applicants. 'It wasn’t difficult at all. You could write a script in 20 minutes that literally pulls every single SMS and email,' he said. By examining the website's code, Jordan found unsecured API endpoints for the admin dashboard, enabling actions such as declining funding requests, changing banking details, or withdrawing active funding.

These flaws build on NSFAS's ongoing ICT problems, including payment backlogs and manual processes that have caused student hardships. In 2024, former administrator Freeman Nomvalo warned a parliamentary committee that the systems were vulnerable to cyberattacks, noting risks to student information.

Jordan highlighted potential consequences: fraudsters could redirect funding to their own accounts or sell leaked data on the dark web. The brothers first tried contacting NSFAS directly but received no response. They then reached out via MyBroadband, alerting the media team and acting CEO Waseem Carrim, who confirmed the issues were addressed.

NSFAS issued a statement acknowledging that logged-in users could view all system-generated messages, including OTPs, and that certain API endpoints were insecure, allowing admin actions like withdrawing appeals. 'NSFAS became aware of a potential security weakness and immediately activated its information security and incident management protocols,' it read. The agency strengthened access controls and enhanced monitoring but did not address accountability for the system's setup.

This incident echoes a 2024 case where Stellenbosch University students exposed fraud vulnerabilities in the SASSA grant system, prompting a parliamentary probe.

مقالات ذات صلة

Dramatic illustration depicting the Coupang data breach, with data spilling from a cracked digital vault and investigators on scene.
صورة مولدة بواسطة الذكاء الاصطناعي

Coupang data breach spanned June to November

من إعداد الذكاء الاصطناعي صورة مولدة بواسطة الذكاء الاصطناعي

A massive data breach at e-commerce giant Coupang exposed personal information of 33.7 million customers from June 24 to November 8. Officials revealed the attacker exploited the company's electronic signature key, prompting a thorough government investigation. The incident has heightened public concerns over South Korea's data protection capabilities.

The National Student Financial Aid Scheme's acting CEO, Waseem Carrim, has detailed a strategy to stabilize operations for the 2026 academic year, addressing funding shortages and accommodation issues. This comes as Finance Minister Enoch Godongwana questions the scheme's future due to its reliance on external providers. Carrim dismissed closure suggestions, emphasizing NSFAS's unique role in student support.

من إعداد الذكاء الاصطناعي

A two-year investigation by the Organisation Undoing Tax Abuse has revealed systemic weaknesses in the National Student Financial Aid Scheme's student accommodation outsourcing, potentially costing taxpayers between R600-million and R1-billion. The probe highlights issues under former CEO Andile Nongogo and ex-chairperson Ernest Khosa. NSFAS acknowledges challenges and is cooperating with investigations.

اكتشفت خرق بيانات هائل يشمل 149 مليون بيانات اعتماد متروكة مكشوفة عبر الإنترنت. يحتوي الكاش السعة 98 جيجابايت على أسماء مستخدمين وكلمات مرور فريدة من خدمات مالية ومنصات تواصل اجتماعي وتطبيقات مواعدة. يكشف الاكتشاف عن الثغرات المستمرة في الأمن الرقمي.

من إعداد الذكاء الاصطناعي

كشفت كندا كومبيوترز وإلكترونيكس عن اختراق بيانات أدى إلى تعريض معلومات العملاء. تعرضت تفاصيل بطاقات الائتمان لدى بعض العملاء المتضررين للاختراق أيضًا. أعلنت الشركة عن الحادث في 2 فبراير 2026.

A new artificial intelligence-based platform has prevented 19 billion won ($13 million) in financial losses from voice phishing scams over the past three months, the financial regulator said. Dubbed the AI-based Phishing Sharing and Analysis Platform (ASAP), it was launched in late October to bolster anti-fraud measures.

من إعداد الذكاء الاصطناعي

قبل عيد الفطر، يحث خبير تكنولوجيا المعلومات من أنتاب سورابايا، سوبانجات، الجمهور على رفع مستوى اليقظة ضد الاحتيالات عبر واتساب والرسائل النصية. يستغل المجرمون الإلكترونيون الارتفاع في المعاملات الرقمية. يحدد مؤسس فيدا نيكي سانتو لوهور طريقتين رئيسيتين: التصيد الاحتيالي والبرمجيات الضارة الشائعة في إندونيسيا.

 

 

 

يستخدم هذا الموقع ملفات تعريف الارتباط

نستخدم ملفات تعريف الارتباط للتحليلات لتحسين موقعنا. اقرأ سياسة الخصوصية الخاصة بنا سياسة الخصوصية لمزيد من المعلومات.
رفض