Brothers uncover vulnerabilities in NSFAS student data system

Two information-technology-savvy brothers have discovered serious flaws in the National Student Financial Aid Scheme's ICT system, potentially exposing millions of students' personal details, including bank accounts, to scammers. The vulnerabilities allowed access to sensitive messages, one-time pins, and even administrative functions like altering funding. NSFAS has since patched the most critical issues after being alerted.

Connor Bettridge, a computer science student at Varsity College in Cape Town, stumbled upon the issues while assisting with an NSFAS funding application. He accessed the portal's communication page and viewed students' addresses, gender, income, and bank details. His older brother, Jordan Bettridge, who works in insurance technology, investigated further.

Jordan described how the system allowed anyone to access all SMSes and emails sent by NSFAS since 2022, including one-time pins and personal information for between half a million and a million applicants. 'It wasn’t difficult at all. You could write a script in 20 minutes that literally pulls every single SMS and email,' he said. By examining the website's code, Jordan found unsecured API endpoints for the admin dashboard, enabling actions such as declining funding requests, changing banking details, or withdrawing active funding.

These flaws build on NSFAS's ongoing ICT problems, including payment backlogs and manual processes that have caused student hardships. In 2024, former administrator Freeman Nomvalo warned a parliamentary committee that the systems were vulnerable to cyberattacks, noting risks to student information.

Jordan highlighted potential consequences: fraudsters could redirect funding to their own accounts or sell leaked data on the dark web. The brothers first tried contacting NSFAS directly but received no response. They then reached out via MyBroadband, alerting the media team and acting CEO Waseem Carrim, who confirmed the issues were addressed.

NSFAS issued a statement acknowledging that logged-in users could view all system-generated messages, including OTPs, and that certain API endpoints were insecure, allowing admin actions like withdrawing appeals. 'NSFAS became aware of a potential security weakness and immediately activated its information security and incident management protocols,' it read. The agency strengthened access controls and enhanced monitoring but did not address accountability for the system's setup.

This incident echoes a 2024 case where Stellenbosch University students exposed fraud vulnerabilities in the SASSA grant system, prompting a parliamentary probe.

관련 기사

Dramatic illustration depicting the Coupang data breach, with data spilling from a cracked digital vault and investigators on scene.
AI에 의해 생성된 이미지

쿠팡 대규모 데이터 유출 사건, 6월부터 11월까지 지속

AI에 의해 보고됨 AI에 의해 생성된 이미지

전자상거래 대기업 쿠팡의 고객 3,370만 명 개인정보가 유출된 대규모 해킹 사건이 6월 24일부터 11월 8일까지 지속된 것으로 확인됐다. 정부는 전자 서명 키가 악용된 점을 밝히며 철저한 조사를 지시했다. 이 사건은 한국의 데이터 보호 능력에 대한 공공의 우려를 높이고 있다.

The National Student Financial Aid Scheme's acting CEO, Waseem Carrim, has detailed a strategy to stabilize operations for the 2026 academic year, addressing funding shortages and accommodation issues. This comes as Finance Minister Enoch Godongwana questions the scheme's future due to its reliance on external providers. Carrim dismissed closure suggestions, emphasizing NSFAS's unique role in student support.

AI에 의해 보고됨

A two-year investigation by the Organisation Undoing Tax Abuse has revealed systemic weaknesses in the National Student Financial Aid Scheme's student accommodation outsourcing, potentially costing taxpayers between R600-million and R1-billion. The probe highlights issues under former CEO Andile Nongogo and ex-chairperson Ernest Khosa. NSFAS acknowledges challenges and is cooperating with investigations.

A massive data breach has come to light, involving 149 million credentials left exposed online. The 98GB cache includes unique usernames and passwords from financial services, social media, and dating apps. The discovery highlights ongoing vulnerabilities in digital security.

AI에 의해 보고됨

Canada Computers & Electronics has disclosed a data breach that exposed customer information. Some affected customers also had their credit card details compromised. The company announced the incident on February 2, 2026.

금융감독원이 발표한 바에 따르면, 인공지능(AI) 기반 플랫폼이 지난 3개월 동안 보이스 피싱 사기로 인한 19억 원(약 1천3백만 달러)의 재정 손실을 방지했다. 이 플랫폼은 지난 10월 말에 출시된 AI 기반 피싱 공유 및 분석 플랫폼(ASAP)으로, 금융 기관 간 정보 공유를 통해 사기 행위를 차단한다.

AI에 의해 보고됨

Ahead of Idul Fitri, IT expert from Untag Surabaya, Supangat, urges the public to heighten vigilance against scams via WhatsApp and SMS. Rising digital transactions are exploited by cybercriminals. Vida founder Niki Santo Luhur identifies two main methods: phishing and malware prevalent in Indonesia.

 

 

 

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부