Brothers uncover vulnerabilities in NSFAS student data system

Two information-technology-savvy brothers have discovered serious flaws in the National Student Financial Aid Scheme's ICT system, potentially exposing millions of students' personal details, including bank accounts, to scammers. The vulnerabilities allowed access to sensitive messages, one-time pins, and even administrative functions like altering funding. NSFAS has since patched the most critical issues after being alerted.

Connor Bettridge, a computer science student at Varsity College in Cape Town, stumbled upon the issues while assisting with an NSFAS funding application. He accessed the portal's communication page and viewed students' addresses, gender, income, and bank details. His older brother, Jordan Bettridge, who works in insurance technology, investigated further.

Jordan described how the system allowed anyone to access all SMSes and emails sent by NSFAS since 2022, including one-time pins and personal information for between half a million and a million applicants. 'It wasn’t difficult at all. You could write a script in 20 minutes that literally pulls every single SMS and email,' he said. By examining the website's code, Jordan found unsecured API endpoints for the admin dashboard, enabling actions such as declining funding requests, changing banking details, or withdrawing active funding.

These flaws build on NSFAS's ongoing ICT problems, including payment backlogs and manual processes that have caused student hardships. In 2024, former administrator Freeman Nomvalo warned a parliamentary committee that the systems were vulnerable to cyberattacks, noting risks to student information.

Jordan highlighted potential consequences: fraudsters could redirect funding to their own accounts or sell leaked data on the dark web. The brothers first tried contacting NSFAS directly but received no response. They then reached out via MyBroadband, alerting the media team and acting CEO Waseem Carrim, who confirmed the issues were addressed.

NSFAS issued a statement acknowledging that logged-in users could view all system-generated messages, including OTPs, and that certain API endpoints were insecure, allowing admin actions like withdrawing appeals. 'NSFAS became aware of a potential security weakness and immediately activated its information security and incident management protocols,' it read. The agency strengthened access controls and enhanced monitoring but did not address accountability for the system's setup.

This incident echoes a 2024 case where Stellenbosch University students exposed fraud vulnerabilities in the SASSA grant system, prompting a parliamentary probe.

Makala yanayohusiana

Dramatic illustration depicting the Coupang data breach, with data spilling from a cracked digital vault and investigators on scene.
Picha iliyoundwa na AI

Coupang data breach spanned June to November

Imeripotiwa na AI Picha iliyoundwa na AI

A massive data breach at e-commerce giant Coupang exposed personal information of 33.7 million customers from June 24 to November 8. Officials revealed the attacker exploited the company's electronic signature key, prompting a thorough government investigation. The incident has heightened public concerns over South Korea's data protection capabilities.

A security breach in the National Senior Certificate exams has been uncovered in Gauteng, where pupils at seven Pretoria schools accessed leaked papers and marking guidelines for three subjects. The Department of Basic Education detected the anomaly through its robust marking system, leading to the suspension of two staff members and a national investigation. Basic Education Minister Siviwe Gwarube emphasized the system's effectiveness in identifying the issue promptly.

Imeripotiwa na AI

Deputy Minister of Higher Education and Training, Dr Nomusa Dube-Ncube, highlighted ongoing challenges in admitting more matriculants to higher learning institutions despite rising pass rates. Speaking in Cape Town, she discussed departmental efforts to streamline processes amid limited resources. Improvements to the NSFAS application system aim to ease access for students nationwide.

State-owned PetroSA sought a R3.5-billion grant from the National Skills Fund in May 2024 to train 5,500 artisans, but documents reveal R1.2-billion was intended for repairing its offshore oil rig. The scheme, proposed by Equator Holdings, ultimately collapsed without funding. It highlights vulnerabilities in the fund meant for youth training amid high unemployment.

Imeripotiwa na AI

Mamlaka ya Kitaifa ya Usafiri na Usalama imewahadharisha madereva wa Kenya dhidi ya ulaghai unaotumia SMS bandia zinazodai malipo ya haraka kwa makosa ya trafiki. Ujumbe huu unatoka wakati wa hatua mpya za serikali kuimarisha usalama barabarani wakati wa sikukuu. Madereva wameelezwa kuto bonyeza viungo au kujibu ujumbe hizo.

Police conducted a second day of raids at e-commerce giant Coupang's headquarters over a massive data breach affecting 33.7 million customers. The suspect is a former Chinese developer who worked on the company's authentication system. Prime Minister Kim Min-seok described the incident as 'beyond serious' and vowed strict action.

Imeripotiwa na AI

South Africa's tech sector faces a severe skills crisis, with unfilled AI and data science jobs amid high youth unemployment. HyperionDev CEO Riaz Moola proposes bootcamps as a 'finishing school' for computer science graduates to bridge the gap. The shortage could cost the economy up to R124-billion by 2027.

Jumatatu, 2. Mwezi wa pili 2026, 10:58:13

SAPS forensic lab issues exposed at Madlanga Commission

Jumatatu, 2. Mwezi wa pili 2026, 10:02:41

Canada Computers reveals customer data breach

Jumapili, 25. Mwezi wa kwanza 2026, 18:07:30

BCA warns customers to beware of phishing scams via fake websites

Ijumaa, 23. Mwezi wa kwanza 2026, 02:03:13

Huge data leak exposes 149 million credentials without protection

Ijumaa, 16. Mwezi wa kwanza 2026, 04:50:43

Information regulator orders JSE to disclose suspicious trades

Ijumaa, 9. Mwezi wa kwanza 2026, 09:22:21

Umalusi greenlights 2025 NSC results despite contained Pretoria exam leak

Jumanne, 23. Mwezi wa kumi na mbili 2025, 03:33:58

Hongkongers urged to sign up for eMPF platform against scams

Jumatano, 17. Mwezi wa kumi na mbili 2025, 08:07:12

Suspect arrested in cyberattack on France's Interior Ministry

Jumatatu, 15. Mwezi wa kumi na mbili 2025, 19:00:40

Data breach exposes credit card details of over 5.6 million people

Jumatatu, 15. Mwezi wa kumi na mbili 2025, 14:54:47

Financial ombud recovers R60m and warns of reckless borrowing

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa