The CIPC hack has potentially serious consequences

March 2024 Editor's Choice, Information Security

The South African Companies and Intellectual Property Commission (CIPC) holds the registration details of companies, co-operatives, and intellectual property rights within a vast database that includes ID numbers, addresses, contact information, and more. The CIPC was recently compromised in a hack that left millions of companies vulnerable.


Richard Frost

Richard Frost, Head of Consulting at Armata, points out that the lack of visibility into the stolen information is a real concern, as some of the data should not be in the public domain, much less in the hands of hackers.

“The CIPC site allows organisations and individuals to verify a company using basic information such as the registration number, but the moment you get real information about directors such as their ID and where they live, there is ample opportunity for fraud and identity theft,” he explains. “For example, criminals can order laptops with fake banking information and a fake address using a company's registration and director information. The firm providing those laptops will then chase the company for payment for an order it did not make. Then the company is liable for the costs, not the threat actor.”

In addition to impersonating a director, fraudsters can use the information to email customers of legitimate organisations and claim the company has changed its bank account information. They can provide customers and suppliers with CIPC data that verifies who they are and essentially siphon funds away from the business. Customers will insist they have paid, but the funds have gone to a fraudulent account.

As the extent of the hack emerges, companies need to remain on the alert for at least six to 12 months. This type of attack has a long tail, and organisations need to protect themselves through constant vigilance. The risk is that many companies will not realise they have been targeted until an incident is flagged. This can then cost them significantly in terms of reputational damage, financial loss, and even customers.

“Companies, whether large enterprises or solopreneurs, need to stay close to TransUnion and Experian right now,” says Frost. “You need to see who is opening up accounts in your name. For larger organisations, it is worth taking a leaf out of the financial institution playbook and creating digitally stamped documents to prove that any request or purchase is coming from a legitimate company. Most importantly, though, for companies of all sizes, is to stay close to the credit bureaus so you can quickly catch any unusual activity.”

To mitigate potential customer fallout, companies should contact their customers and highlight the risks, asking them to be aware of any changes in day-to-day interactions and confirm in person if any requested changes are genuine.

“Every single company in South Africa needs to send out an email to customers highlighting the potential risks and giving them insight into how they can prevent them,” concludes Frost. “In addition, individuals need to be aware of fake calls and scams – if a caller says they are from a fraud division, instead of paying or providing personal information, suggest calling them back first. The CIPC hack essentially demands that companies and individuals increase their vigilance across all platforms so they do not fall victim to crime.”

For many companies and individuals, a successful hack or case of fraud can leave them financially destitute, and there are limited legal and governmental protections in place. While this landscape is changing, the best step forward is to be on constant alert to avoid the need to take the CIPC on a long, drawn-out court case or rebuild your business from scratch.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.