The findings, prompted by concerns raised by Stellenbosch University computer science students, highlight the ease with which fraudsters can exploit the system.
The Portfolio Committee on Social Development has welcomed the investigation's initial report, which substantiates claims of widespread security breaches within the South African Social Security Agency (Sassa)-managed system.
Student Findings Trigger Official Probe
Last year, Stellenbosch University students conducted vulnerability tests that exposed critical flaws in the SRD grant platform. Their findings included an unusually high number of applications from individuals born in 2005, suggesting potential mass fraud.
They also discovered that fraudulent applications were being approved using their own ID numbers, while legitimate beneficiaries were denied. A campus survey further revealed that numerous students had fraudulent applications lodged in their names without their consent.
In response, the Department of Social Development (DSD) launched an investigation, with the first phase focusing on the online system's security. This audit confirmed the students' concerns.
Malicious Websites Exploit Personal Data
The audit identified numerous malicious websites mimicking the official SRD application platform. These sites, using deceptive domain names, tricked beneficiaries into providing personal information, which fraudsters then exploited to access grant payments.
Social Development Minister, Sisisi Tolashe, stated: "The findings from phase one will guide a more comprehensive phase two investigation, which will focus on potential fraud and systemic flaws across the entire social grant programme. The goal is to prevent ineligible individuals from receiving benefits."
Sassa Announces Action Plan to Fortify Security
Sassa has announced a comprehensive action plan to improve its systems and protect beneficiaries' information. This includes implementing stronger data protection protocols, enhancing biometric verification checks, conducting regular system updates, and removing fraudulent websites.
The Portfolio Committee will monitor Sassa’s progress in implementing the report’s recommendations. The committee expects quarterly reports from the department on Sassa's implementation of the recommendations made in the investigation report on the SRD grant payment system.