Millions of South Africans relying on the Social Relief of Distress (SRD) grant face heightened fraud risks, according to a recent investigation by the Department of Social Development (DSD). The investigation, prompted by discoveries made by Stellenbosch University students, has revealed critical security weaknesses in the SRD grant online system.
Last year, two computer science students uncovered significant bugs and fraud within the Sassa SRD grant system. Their legal vulnerability tests revealed alarmingly high application rates for individuals born in 2005, indicating mass fraudulent activity, and the approval of fraudulent applications using their ID numbers, while legitimate beneficiaries were denied.
A campus survey further highlighted the widespread nature of the problem, revealing numerous students had fraudulent applications filed in their names without their knowledge.
Investigation Uncovers Malicious Websites and Systemic Flaws
Social Development Minister Sisisi Tolashe stated that the audit results from phase one will inform phase two, a deeper investigation into potential fraud and systemic flaws across the social grant programme, particularly focusing on how ineligible individuals receive benefits.
The phase one report, assessing the SRD grant online system's vulnerability, revealed critical security weaknesses that expose vulnerable applicants to fraud. The audit identified numerous unidentified, malicious websites mimicking the authentic SRD application platform, using seemingly legitimate domain names like ".org" and ".co.za."
These sites deceive beneficiaries into providing personal information, which fraudsters can then use to access grant payments.
Sassa Implements Security Enhancement Measures
Sassa has announced a comprehensive action plan to improve its systems and protect beneficiaries' information. This includes implementing data protection protocols, enhanced biometric verification checks, regular system updates, and the removal of fraudulent websites.
A key component of this plan is the transition to the "POST" method for online data transmission, providing a more secure channel for applicant information. Sassa will also implement "rate limits" to restrict the number of online requests, blocking automated attacks and excessive traffic.
The agency has committed to regular software updates and security patches to close potential loopholes and strengthen defences against cyber threats. Biometric verification mechanisms will be introduced to prevent impersonation of legitimate beneficiaries.
Sassa will also undertake a long-term initiative to remove fraudulent websites and online content.