Lesufi’s e-Government ignored Auditor-General’s warning before jobs portal data breach

July 13, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: dagauteng.org.za

Threat Risk: Medium
Victim: Gauteng Department of e-Government
Incident: Data breach of the Gauteng Government jobs portal e-Recruitment system.
Impact: Exposure of PII, including IDs, CVs, and contact details for 283 applicants.
Attacker: Unidentified threat actors
Analysis: The breach occurred via a compromised user account within the e-Recruitment system. A lack of Network Access Control (NAC), despite warnings from the Auditor-General, left the network vulnerable. This incident underscores the risk of ignoring audit recommendations due to budgetary constraints.
Recommendations: Deploy Network Access Control (NAC) to limit unauthorized movement within the government network.; Implement multi-factor authentication (MFA) to mitigate the risk of compromised user accounts.; Establish a mandatory cycle of penetration testing and security audits following any data exposure.
Source: DA Gauteng

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *