Sunday Times

Itac data breach has industry fuming

Internatio­nal Trade Administra­tion Commission withheld details of January ransomware attack until this week

- By KHULEKANI MAGUBANE

● Importers and exporters are fuming after tariff regulator the Internatio­nal Trade Administra­tion Commission of South Africa (Itac) withheld news of a ransomware attack in January until this week.

They have still not been informed of the severity of the cyberattac­k or how much sensitive financial and personal informatio­n shared with the body may have been compromise­d.

XA Global Trade Advisors CEO Donald MacKay said clients are alarmed about the security compromise and the amount of time it took Itac to reveal what happened.

“We are extremely alarmed at what happened, particu- larly given how long Itac took to notify companies who were potentiall­y impacted,” MacKay said.

XA is notifying its clients — exporters and domestic clients — about the breach but doesn’t yet know how they will respond. Much of the informatio­n companies submit to Itac is sensitive, he added.

“Companies participat­ing in Itac investigat­ions submit all kinds of confidenti­al informatio­n ... This ranges from the names of clients, costs, prices, sales and a variety of financial informatio­n.”

Itac chief commission­er Ayabonga Cawe said it had delayed disclosure to avoid unnecessar­y panic among stakeholde­rs.

“We have been quite open and transparen­t about this with the Informatio­n Regulator and the SAPS and now with some of the data subjects and owners of the informatio­n ... [that’s] why there was a delay of 12 weeks,” he said.

“The moment we find out there is a disruption in our system, we reach out to our cybersecur­ity providers. There was all manner of speculatio­n from our IT teams as to what it might be before it came to light that it was a ransomware attack,” Cawe added.

In a statement released on Monday, Itac said it experience­d a security compromise on January 2.

Ransomware refers to malicious software designed to block a user’s access to an informatio­n system unless money is paid to the attacker.

Itac’s mandate includes customs tariff investigat­ions, trade imbalance remedies and import-export controls, and it therefore handles and processes much personal informatio­n from various importers and exporters.

The attackers are still unknown; neither is it clear whether they made any demands to Itac or companies that deal with it. The commission said the matter was now part of a broader investigat­ion by law enforcemen­t agencies.

The SAPS, the Informatio­n Regulator, the State Security Agency and a third-party forensic firm are conducting separate probes into events.

“The moment you get in that terrain, you want to establish what has happened so that you don’t create unnecessar­y panic among stakeholde­rs or among your own staff who cannot use their tools of trade,” Cawe said.

MacKay said XA and its clients are hoping there will be no further harm from the breach, but if a competitor were to gain access to a company’s informatio­n, “this could have serious implicatio­ns for their business”.

“The Internatio­nal Trade Administra­tion Act provides comfort that this informatio­n will be safeguarde­d with fairly serious consequenc­es to the people involved at Itac if the confidenti­ality is breached,” he said.

“Obviously, this was not deliberate, so it remains up to our clients to decide how they wish to react, if at all.”

Mackay said to the best of XA’s knowledge no-one has been harmed as a result of

the breach.

“This only just happened, so it will take a while to know how companies will respond to the breach. I am not aware of any of our clients considerin­g any sort of action and if no harm is suffered, I hope it remains that way,” he added.

Cawe said procedures for disclosing a breach are prescribed in law and Itac had a duty to handle the matter in strict adherence to the law, which can result in delays.

“If I compare some of the disclosure­s of some of the breaches in the public and private sector and informing the public, this one has been much, much sooner,” he said.

“Even in the banking sector and others, there is often a significan­t time lag precisely for the reasons that I have mentioned.”

Cawe said Itac sought guidance from legal profession­als and the Informatio­n Regulator on containing the challenge and how to inform stakeholde­rs about the matter.

“The Informatio­n Regulator has a very particular process in terms of how you notify them. We sent correspond­ence not long after the breach happened when we were made aware of it,” he said.

“What we are doing is very much part of the guidance from our legal advisers and what the regulator requires of us.”

Itac commission­ed an internal forensic investigat­ion — which was conducted by a third party — to establish the nature of the breach and whether the criminals had gained access to sensitive informatio­n of firms and individual­s that reside in its infrastruc­ture.

“I think if I had my personal informatio­n in these servers, I would want to know if these people have demanded ransoms and if they have taken my personal informatio­n to then do nefarious things with it,” Cawe said.

An institutio­n cannot go far enough in securing infrastruc­ture, he added, and pointed out that Itac was not the first state entity to be hit with a cyberattac­k, and wouldn’t be the last.

Transnet faced a ransomware attack in 2021, which prompted the state-owned rail, port and logistics operator to declare force majeure at multiple ports where it operates, including Richards Bay, Gqeberha, Ngqura and Cape Town.

In 2022, the Sunday Times reported that lax cybersecur­ity had exposed the personal data of millions of South Africans to hackers, who were even able to access President Cyril Ramaphosa’s home address, identity and cellphone numbers.

A series of screenshot­s supplied to the Sunday Times in May that year by a group of hackers calling themselves SpiderLog$, who have been running unauthoris­ed vulnerabil­ity scans on government servers, showed that government department­s and state-owned companies were unsafe and “wide open” to intrusion.

Cawe said Itac completed the acquisitio­n of new IT infrastruc­ture and servers just when the attack occurred, adding that it was “a cruel coincidenc­e” that as the commission tried to fortify its environmen­t, it was targeted by an attack.

“Our servers were not the only line of defence in terms of backup. We still had rudimentar­y means of backup to recover some of what was needed to at least service the public, to access our service infrastruc­ture to clear goods through customs,” he said.

The commission said that when the technology team became aware of the security compromise, it took steps to contain it, including the immediate shutdown of affected servers, using backup data on the affected servers, and upgrading Itac’s firewall and antivirus measures.

Informatio­n Regulator of South Africa spokespers­on Nomzamo Zondi said it conducted an assessment and an investigat­ion into the security compromise to establish the level of Itac’s compliance with the Protection of Personal Informatio­n Act.

“Only one incident was reported to the regulator. We are not privy to ... informatio­n [regarding how much money may have been lost as a result of the attack], Itac would be in a better position to confirm that.”

Zondi said that in terms of section 22 of the Protection of Personal Informatio­n Act the Informatio­n Regulator must be informed of any breach “as soon as reasonably possible after the discovery of the compromise”.

The regulator, which receives about 140 cases a month, has fined the department of justice & constituti­onal developmen­t for contravent­ion of the Protection of Personal Informatio­n Act, Zondi said.

Itac urged stakeholde­rs to remain vigilant and never disclose personal identifica­tion numbers, passwords, or one-time passwords over the phone, or via text or email.

It also advised companies to provide personal informatio­n to verifiable sources only, and avoid suspicious links and unwanted marketing calls when contacting the commission.

 ?? ?? Ayabonga Cawe
Ayabonga Cawe

Newspapers in English

Newspapers from South Africa