Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Nedbank hires MTN's former tech chief as group CIO - Nikos Angelopoulos

      Nedbank hires MTN’s former tech chief as group CIO

      31 July 2026
      Eskom's diesel bill falls 86% as breakdowns hit eight-year low

      Eskom’s diesel bill falls 86% as breakdowns hit eight-year low

      31 July 2026
      Ramaphosa signs off on taking the grid away from Eskom

      Ramaphosa signs off on taking the grid away from Eskom

      31 July 2026
      Microsoft just had the biggest day in stock market history

      Microsoft just had the biggest day in stock market history

      31 July 2026
      MTN Nigeria's growth engine stalled in second quarter - Karl Toriola

      MTN Nigeria’s growth engine stalled in second quarter

      31 July 2026
    • World
      Meta AI will now tell parents if their teen is in crisis

      Meta AI will now tell parents if their teen is in crisis

      17 July 2026
      IBM shares crash 25% as AI upends software spending - Arvind Krishna

      IBM shares crash 25% as AI upends software spending

      15 July 2026
      Jony Ive's first OpenAI device: an AI smart speaker - Jony Ive and Sam Altman

      Jony Ive’s first OpenAI device: an AI smart speaker

      15 July 2026
      Stripe, Advent in talks to buy PayPal for $53-billion

      Stripe, Advent in talks to buy PayPal for $53-billion

      15 July 2026
      Memory crisis sends smartphone market into steep decline

      Memory crisis sends smartphone market into steep decline

      13 July 2026
    • In-depth
      The plan to stop AI from breaking the world - Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
    • TCS
      TCS+ | Why South African workers must become supervisors of digital labour - Accelera Digital Group Cliff de Wit

      TCS+ | Why South African workers must become supervisors of digital labour

      31 July 2026
      TCS | Rapid deployment rules can't work without municipalities: ACT - Nomvuyiso Batyi

      TCS | Icasa’s rules skip the real bottleneck: ACT

      30 July 2026
      TCS+ | iStore Business on why Apple makes sense for SMEs - Sudesh Pillay and Tamia Nontsikelelo

      TCS+ | iStore Business on why Apple makes sense for SMEs

      30 July 2026
      TCS+ | A smarter approach to cloud for South African businesses - Joel Chacko and Jonathan Oaker

      TCS+ | A smarter approach to cloud for South African businesses

      28 July 2026
      TCS | How Optasia lends billions to people banks can't see - Salvador Anglada

      TCS | How Optasia lends billions to people banks can’t see

      23 July 2026
    • Opinion
      The author, Jannie van Zyl

      Selling vapour is corporate suicide in slow motion

      16 July 2026
      Brazil's online gambling crackdown is a lesson for South Africa

      How Amazon outmanoeuvred Starlink in South Africa

      15 July 2026
      The Popia problem with agentic AI - Herman Haasbroek

      The Popia problem with agentic AI

      14 July 2026
      The author, Fanie van Rooyen

      South Africa can still catch the AI wave – here’s how

      7 July 2026
      The author, Fanie van Rooyen

      The AI utopia South Africa can’t afford

      1 July 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM Telecom
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Public sector » How South Africa’s social grants system was defrauded on a massive scale

    How South Africa’s social grants system was defrauded on a massive scale

    It has become clearer how the SRD grant system has been defrauded at huge scale.
    By Nathan Geffen6 January 2025
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    How South Africa's social grants system was defrauded on a massive scaleThe Social Relief of Distress (SRD) grant was introduced during the Covid pandemic to assist people in dire need. About nine million of these R370 grants are paid out monthly now. It is potentially the basis for a universal basic income grant.

    Activist Israel Nkuna has for years been warning of fraudulent applications for the SRD grant, and that these fraudulent applications have been squeezing out legitimate applicants by using their ID numbers without permission. GroundUp, too, has reported this problem. Then in October, we published an article by Stellenbosch University students who discovered a massive number of fraudulent applications for the SRD grant, and evidence that at least some of these fraudulent applications were succeeding.

    Since then, it has become clearer how the SRD grant system has been defrauded at scale. It involves six steps:

    • First, obtain ID numbers and their associated names from one of the various large leaks of South African data.
    • Second, open improperly verified accounts with Shoprite or TymeBank, or possibly some other banks as well. This could be done on a laptop or phone without leaving one’s home. Shoprite and TymeBank have in recent months tightened up their bank account application processes, so fraudsters can no longer continue to do this.
    • Third, obtain improperly verified Sim cards. This is easily done by simply going to a local dodgy cellphone shop. But until recently it could even be done entirely online by registering free electronic Sim cards through Me&You Mobile. This, too, has since been stopped.
    • Fourth, use the ID number, telephone number and bank account obtained in the first three steps to apply for an SRD grant.
    • Fifth, wait for the grant to be paid into the account opened in step two. It seems that every month, Sassa sends ID numbers of applicants to the banks, Sars and Nsfas to check if applicants pass the means test. If the applicant isn’t paying income tax, doesn’t receive money from Nsfas and has income to their bank account of less than R625/month, the grant is paid.
    • Sixth, launder the SRD money by transferring it out of the bank account. There are various ways to do this, which we do not describe here.

    Doing the above for one SRD grant is not worth the effort. But a determined fraudster or group of fraudsters could make dozens or even hundreds of applications a day. At one point it was possible to carry out the entire process described above using only a laptop. It would also be possible to write a computer program to automate the process, but such sophistication would be unnecessary: going to a shop to buy Sim cards and manually making lots of applications would be very profitable.

    As far as we can tell, it is no longer possible – or at least no longer easy – to make new fraudulent applications. But it’s likely that many fraudulent applications made for years after the grant was introduced are still passing the monthly means test and receiving SRD grants.

    Vodacom fires hundreds of workers in crime crackdownSassa needs to act

    Sassa, together with companies that have received large numbers of SRD grants like TymeBank and Shoprite, can take at least these steps to prevent this fraud:

    • Insist banks only accept SRD grants for biometrically verified people who have been validated with a fingerprint or facial scan.
    • Remove third-party access to the Sassa grant application system, except to authorised institutions that have a legitimate need to access the system. (Sassa says it has now done so.)
    • Limit the number of requests a single computer device can make to the Sassa website so that programs making tens, hundreds or thousands of requests to it per second fail. (Sassa says it has now done so.)
    • Audit all current SRD grant applications to identify the scale of the fraud, remove fraudulent applications – identifying these might be difficult — and insist that suspicious applications undergo verification. (Sassa says an audit “would not assist”. But TymeBank says it is “conducting an analysis of transacting behaviour on accounts opened prior to August 2024 that receive grant payments to identify those that are non-legitimate grant beneficiaries”.)

    While we do not have enough information to quantify it, we suspect the scale of SRD fraud is very large. Not only does this bleed money from the social grant system, but every fraudulent application using someone else’s ID potentially denies a legitimate SRD grant recipient the possibility of getting the grant because their ID number is being used by someone else. At best, someone who is a victim of ID fraud has to navigate their way through a horrible bureaucratic process to undo the fraudulent application.

    Response by Sassa

    Sassa is aware of fraud risk within the social grants space and works closely with various stakeholders within the financial sector as well as law enforcement to mitigate this risk and apprehend those responsible for this criminal activity.

    With regards to the banks mentioned, Sassa works with all banks that are willing to cooperate with us. However, it would not be appropriate for us to comment on fraud within an individual bank’s environment.

    Should you have any additional information regarding fraud, we would encourage you to either share this data with our fraud department, or directly with the SAPS. Details of opened cases can be provided to you should you wish to go directly to the SAPS.

    Response specific to recommendations proposed by GoundUp

    Insist banks only accept SRD grants to biometrically verified people who have been validated with a fingerprint or facial scan.

    Sassa unfortunately can’t manage a bank’s operations, or direct how they choose to engage with their clients. However, we do factor in a bank’s risk profile into our fraud risk mitigation measures.

    Remove third-party access to the Sassa grant application system, except to authorised institutions that have a legitimate need to access the system.

    Sassa implements strict firewall and access policies for any third party or authorised institutions with which it interfaces for the purposes of data sharing or access to its environment and databases.

    Limit the number of requests a single computer device can make to the Sassa website so that programs making tens, hundreds or thousands of requests to it per second fail.

    Sassa has implemented content security policy (CSP) as an added layer of security that helps to detect and mitigate certain types of attacks and data injection attacks. This provides controls that allow only approved sources of content that browsers should be allowed to load on the page as well as blocking unauthorised requests, including:

    • High-frequency requests that exceed normal user behaviour;
    • Requests with invalid or partial data (for example, incorrect combinations of ID numbers and phone numbers); and
    • Requests from suspicious or known malicious IP addresses.

    Audit all current SRD grant applications to identify the scale of the fraud, remove fraudulent applications — identifying these might be difficult — and insist that suspicious applications undergo verification.

    An audit would not assist in identifying fraudulent applications if the fraud in case is identity theft, as all records of the applicant would match that of the alleged victim. The process that Sassa currently follows is to flag any suspected fraudulent application, and then require biometric confirmation if the applicant is the real person. The biometric identification does, however, pose a challenge to many applicants (which is the main reason we are not using it for all applicants). Thus, at this stage it’s too early to report on whether those applications that are suspected of fraud and not responded to are genuine fraud cases or if they are merely access challenges. The process has already commenced.

    Unfortunately, fraud has a negative impact on victims, and as such additional verification steps are required. Sassa has also reprioritised significant resources to be able to equip its local offices with self-help kiosks by the new financial year. This will enable us to assist applicants who do not have access to the necessary technology.

    Response by Shoprite

    Fraudulent SRD grant applications are no longer possible via a money market account. All new accounts are now biometrically onboarded.

    To safeguard our customers’ money, all suspicious transactions are reported, and accounts are immediately blocked. An account can only be unblocked pending the successful submission of additional verification documents.

    Sassa has removed third-party access to the grant application system. We would welcome any additional safety measures and checks implemented by Sassa to further combat any fraudulent activities pertaining to SRD grants.

    Response by TymeBank

    From August 2024, TymeBank no longer allows Sassa grant recipients to receive grant payments into non-biometrically verified TymeBank accounts. If they would like to use their TymeBank account to receive a grant, they must upgrade their account and complete the biometric verification process and KYC (“know your client”).

    Over the past few months, we’ve been reaching out to account holders who still have non-biometric accounts to get them to upgrade their accounts biometrically. At the same time, we are conducting an analysis of transacting behaviour on accounts opened prior to August 2024 that receive grant payments to identify those that are non-legitimate grant beneficiaries. This project is expected to be completed shortly. By the end of January 2025, those accounts that are non-biometrically verified will be suspended, pending successful biometric verification.

    We continue to work closely with Sassa to combat fraud within the social grant system.

    Get breaking news from TechCentral on WhatsApp. Sign up here.

    • This article was originally published by GroundUp. It is republished by TechCentral under a Creative Commons Attribution-NoDerivatives 4.0 International Licence. Read the original article

    Don’t miss:

    Letter | Alleged Sassa fraud underscores urgency for better data management

    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Sassa SRD grant
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleChina to subsidise consumer smartphone purchases
    Next Article LEO services like Starlink are booming – what comes next will be trickier

    Related Posts

    fingerprint

    Fingerprints, facial scans now mandatory for Sassa grants

    27 August 2025

    Compulsory biometric tests for some Sassa beneficiaries

    24 April 2025
    Letter | Alleged Sassa fraud underscores urgency for better data management

    Letter | Alleged Sassa fraud underscores urgency for better data management

    30 October 2024
    Company News
    Domains.co.za launches self-hosted n8n VPS hosting

    Domains.co.za launches self-hosted n8n VPS hosting

    31 July 2026
    Smarter.tech '26 shows why smarter technology begins with context - Obsidian Systems

    Context is the missing piece in enterprise AI: Obsidian

    31 July 2026
    Huawei launches 12 intelligent transport solutions in South Africa - Sam Tang

    Huawei launches 12 intelligent transport solutions in South Africa

    30 July 2026
    Opinion
    The author, Jannie van Zyl

    Selling vapour is corporate suicide in slow motion

    16 July 2026
    Brazil's online gambling crackdown is a lesson for South Africa

    How Amazon outmanoeuvred Starlink in South Africa

    15 July 2026
    The Popia problem with agentic AI - Herman Haasbroek

    The Popia problem with agentic AI

    14 July 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Nedbank hires MTN's former tech chief as group CIO - Nikos Angelopoulos

    Nedbank hires MTN’s former tech chief as group CIO

    31 July 2026
    Eskom's diesel bill falls 86% as breakdowns hit eight-year low

    Eskom’s diesel bill falls 86% as breakdowns hit eight-year low

    31 July 2026
    Ramaphosa signs off on taking the grid away from Eskom

    Ramaphosa signs off on taking the grid away from Eskom

    31 July 2026
    TCS+ | Why South African workers must become supervisors of digital labour - Accelera Digital Group Cliff de Wit

    TCS+ | Why South African workers must become supervisors of digital labour

    31 July 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}