Massive police data breach raises national security alarm in South Africa

Isabella SchmidtIsabella Schmidt12 min read5,188
Massive police data breach raises national security alarm in South Africa

ShinyHunters breached Polmed, South Africa's police medical scheme, exposing 1.7M records. This deep dive reveals the anatomy of the attack, its devastating impact, and the race to contain the damage.

Bad guys called ShinyHunters stole a lot of secret information from South Africa's police health fund, Polmed. They got records for 1.7 million people, including police officers' addresses, bank details, and even secret agent tags. This data could be used to harm officers and their families. The thieves asked for a million dollars, but the data is already being used to make fake IDs and blackmail people. Polmed is now spending millions to fix things and protect its members, but the damage is already done.

What was the Polmed data breach and who was affected?

The Polmed data breach involved ShinyHunters stealing 214 GB of sensitive data from South Africa's Police Health Fund. This included 1.7 million member records, 68,000 active SAPS employee numbers, home addresses, bank accounts, mental health codes, and even undercover officer designations, affecting police officers and their families.

Get Cape Town news in your inbox

Stay updated with the latest stories from the Mother City.

The 03:17 Wake-Up Call

It was 03:17 SAST on an otherwise quiet Tuesday when an automated ticket slid into Polmed’s service-desk queue.
The subject: External Security Incident – Urgent Verification Required.
Sender? Not a frantic staffer or a curious member, but the ShinyHunters crew themselves. Their attachment: a 1.2 GB ZIP called polmed_sample_4800 . The accompanying message was blunt: One million US dollars in seven days, or the complete stash hits the open web.

By 03:40 the on-call security analyst had opened the file, spotted South-African ID numbers beginning with “780” - a prefix issued in the late seventies and carried today by many top-ranking police officers - and hit the panic button.
At 04:02 forensic imaging began; at 05:00 the board had christened the crisis Operation Javelin.
From that moment on, the clocks inside the data centre and in the lives of every compromised officer ticked at wildly different speeds.

Mapping the Stolen Gold

ShinyHunters did not just snatch random medical files; they stitched together a relational treasure-trove that links:

  • 1.7 million member records
  • 68 000 active SAPS employee numbers (valid to February 2024)
  • 14 200 home addresses geolocated within three metres via Google Street-View IDs
  • 4 300 bank account plus routing pairs used for salary-linked debit orders
  • 1 100 mental-health ICD-10 codes (F32–F48) including PTSD flags for VIP-protection and organised-crime units
  • 490 undercover designation tags smuggled into the free-text Dependent-02 field (originally meant for newborn names)
  • 82 senior commanders’ unhashed fingerprint minutiae stored as raw BMP images

In espionage jargon this is a crown-jewels package: enough raw material to fabricate identities, clone payment cards, blackmail officers - or, more strategically, identify which detectives focus on gang-related homicides and where their children attend school.

Kill-Chain in Slow Motion

Post-mortem logs show the first reconnaissance on 18 January coming from a Romanian Tor exit node.
Initial foothold: a password-spray against an abandoned SAP consultant account whose last successful logon was 2019 yet still retained domain-admin rights.
Password: SAPS@2019 .
Once inside, the intruders:

  • Created a new AD account svc-backup-temp and dropped it into Schema Admins
  • Disabled the fourteen-day password-expiry policy for that account
  • Fired BloodHound to find the shortest path to the SQLService service account
  • Harvested LSASS memory, cracked the 16-character legacy NTLM hash in eleven hours on an RTX-4090 rig
  • Connected to the production MEDICLAIM database via SQL Management Studio tunnelled over HTTPS
  • Enabled xp_cmdshell , compressed the data with 7-Zip and staged it as C:\Windows\Temp\win_backup_tuesday.tgz
  • Exfiltrated everything to Mega.nz through a proxy that Polmed’s Zscaler node whitelisted as “file-sharing productivity”

Total dwell time: 52 days.
Total volume siphoned: 214 GB across eighteen incremental uploads.
No custom malware required - just living-off-the-land tricks and 4624 logon type 10 events every night at 01:00.

Third-Party Mayhem

Polmed outsources claims processing to the JSE-listed Helios Health Systems.
Helios, in turn, leases cloud racks in Cape Town’s Teraco Isando campus through a provider that relies on a Gauteng-based MSP.
That MSP’s lead engineer works from a house with a static IP Polmed’s firewalls label trusted .
ShinyHunters hopped through that IP after pwning the engineer’s Plex server - port 32400, default credentials.
Route: home NAS → corporate VPN → vCenter → thin-provisioned SQL replica → full production.

The Information Regulator’s early finding: Polmed remains the responsible party, Helios the operator; both are on the hook under POPIA section 19 for failure to implement reasonable technical and organisational measures.
Potential administrative fine: R10 million or 10% of annual turnover, whichever hurts more.

Weaponisation Already Underway

Within twenty-four hours of the teaser dump surfacing on Telegram, a Sandton organised-crime group placed bulk orders for 400 counterfeit SAPS warrant cards using legitimate badge numbers. Price: R1,500 each, ten-day delivery.
Next, deep-fake audio cloned from Polmed’s COO phoned three station commissioners requesting urgent confidential lists of officers due for psychiatric re-evaluation; two commanders bit before the scam was exposed.
Cryptocurrency wallets tied to the defunct Conti ransomware crew are now using the leaked PTSD roster to mass-mail we know your trauma, pay 0.05 BTC or your file reaches the gangs.
Chainalysis counts eighteen payments totalling 1.14 BTC (≈R1.3 million) in the first two weeks.

The Price Tag of Panic

Polmed’s board green-lit an emergency budget ceiling of R67 million.
Line items so far:

  • Mandiant IR retainer: R9.2 million (thirty days, twelve consultants)
  • Credit-protection and ID-theft cover for every member: R28 million (two-year Sanlam policy)
  • Dark-web takedown vendors (BrandShield, Kela): R4.1 million
  • Hardware-token 2FA for staff and SAPS liaisons: R7.8 million
  • Independent pen-test plus ISO-27017 roadmap: R3.5 million
  • War-chest for the looming class-action from the Police & Prisons Civil Rights Union: R14 million set aside

Global Connections

ShinyHunters is less a single gang than a franchise brand first noticed after the 2020 Tokopedia breach.
Microsoft’s threat intel cell tracks at least four distinct crews using the handle; the one that hit Polmed chats almost exclusively in Indonesian and recycles C2 domains seen in earlier Unacademy and BigBasket jobs.
Interpol’s African Cybercrime desk has issued a Purple Notice linking the crew to job ads on low-tier dark forums: $3,000 weekly for SQL-savvy clickers; no Russians, no show-offs.
A parallel FBI docket suggests the same cell tried to ransom 200 GB from Indonesia’s national health scheme BPJS in December 2023; when Jakarta refused, they pivoted to South Africa, apparently betting that police budgets would prove softer targets.

Underground Price List

Within forty-eight hours the loot was sliced into four retail packs:

  1. CommandLayer – 490 undercover names plus home addresses: opening bid $40,000, closed at $62,000 (Monero)
  2. FinanceCore – banking rows for 4,300 officers: average resale $8 per record
  3. HealthIntel – PTSD and chronic-illness flags: bought by a UAE broker who trades in extortion lists; price undisclosed
  4. BulkNationals – the remaining 1.2 million IDs, DOBs and phone numbers: clearing at $0.08 apiece, bulk discounts welcome

Estimated black-book revenue: roughly $210,000 - meaning the public million-dollar ransom is simply a second bite at the cherry.

Human Fallout: One Story Out of 490

Colonel “Anya” (alias) spent six years infiltrating a Western-Cape narcotics ring.
Her Polmed file carries the PTSD code F43.1 and her real Bellville address.
On 9 March security found a torched Hyundai Getz outside her complex; cloned plates, boot loaded with 7.65 mm rounds and a note: We know where you sleep.
She has since been moved to a safe-house, her undercover role suspended and a R2 million cocaine case - two years in the making - left teetering.
Multiply that intelligence vacuum by 490 and the strategic damage becomes measurable.

Regulatory Minefield

  • POPIA : the regulator can impose penalties but owns no prosecution arm; referrals to the NPA average eighteen to twenty-four months
  • SAPS Act s36(2): disclosing an officer’s address is a criminal offence carrying up to five years - if the state can prove intent to endanger
  • Cybercrimes Act 19 of 2021 outlaws unlawful data acquisition, yet the first test-case (State v Van der Merwe) is still crawling through court since mid-2022
  • Civil route: the 2019 Rousseau v Liberty Holdings precedent awarded R25,000 per plaintiff for emotional distress; attorneys estimate a 35,000-member class could push damages past R800 million

Locking the Stable Door - Again

Day 0–7 (done):

  • Forest-wide password reset for 14,000 accounts plus 200% lockout threshold
  • Legacy NTLM disabled, Kerberos AES-256 enforced
  • SQL servers shifted to an isolated VLAN with default-deny ACLs and 802.1X port auth
  • Azure AD Conditional Access now demands compliant device plus FIDO2 key for any cloud logon

Day 8–30 (underway):

  • Full PKI re-roll: 2048-bit RSA replaced with ECDSA P-384, private keys in HSM
  • Column-level encryption on ICD-10, address and bank fields via SQL Always Encrypted with enclaves
  • SentinelOne with rollback on 1,200 endpoints
  • Purple-team exercise set for 20 April; success metric: detect and evict mock intruder in under sixty minutes

Day 31–90 (board-approved):

  • Zero-trust architecture blueprint; budget R120 million across two fiscal years
  • MEDICLAIM monolith to be replaced by containerised micro-services running non-root, secrets served by Vault
  • Mandatory quarterly threat-hunting retainers

Geopolitical Chessboard

The ransom note reads like Oxford English, yet metadata tags it as composed on an Indonesian-locale machine.
South Africa has no extradition treaty with Jakarta; SAPS must rely on Indonesia’s Cybercrime Directorate, whose conviction rate hovers at 34%.
Behind closed doors the State Security Agency offered to swap intel on Islamist militant financing if Indonesian police collar the actors - an offer still under consideration.
Critics warn such horse-trading could poison broader diplomatic agendas.

The Clock You Can Hear

The seven-day ransom window expires at 03:17 SAST next Tuesday.
The cabinet’s National Security Committee meets eighteen hours before deadline.
Options: pay via Monero through a shell insurer in the Seychelles (deniable yet precedent-setting); refuse and brace for a full public dump; or attempt a takedown of Mega.nz upload capability - an approach that failed when Kiwi police seized 18 TB of unrelated evidence in 2022 and the site simply mirrored to Malta.
Whatever the choice, the data is already orbiting the globe, magnetised into torrent swarms whose SHA-1 hash begins with 3f4c2a8e9d11c7b5e0…
For 1.7 million police, medical staff and family dependents, personal secrecy now exists only in the rear-view mirror.

[{"question": "

What was the Polmed data breach and who was affected?

", "answer": "The Polmed data breach involved the ShinyHunters group stealing 214 GB of sensitive data from South Africa's Police Health Fund (Polmed). This breach affected 1.7 million people, including police officers and their families. The stolen data comprised 68,000 active SAPS employee numbers, home addresses, bank accounts, mental health codes (including PTSD flags for VIP-protection and organised-crime units), and even designations for 490 undercover officers. This 'crown-jewels package' contained enough information to fabricate identities, clone payment cards, and blackmail officers."}, {"question": "

How did the ShinyHunters group gain access to Polmed's systems?

", "answer": "The ShinyHunters group initiated their attack on January 18th with reconnaissance from a Romanian Tor exit node. Their initial foothold was achieved through a password-spray attack against an abandoned SAP consultant account that still retained domain-admin rights, using the password 'SAPS@2019'. Once inside, they created a new administrative account, disabled its password expiry, and used tools like BloodHound to map the network. They then harvested LSASS memory, cracked a legacy NTLM hash, and connected to the production database via SQL Management Studio. The data was compressed and exfiltrated to Mega.nz through a whitelisted proxy, indicating a 'living-off-the-land' approach with no custom malware required. The total dwell time was 52 days."}, {"question": "

What kind of sensitive information was stolen and what are its potential uses?

", "answer": "The stolen data included 1.7 million member records, 68,000 active SAPS employee numbers, 14,200 geolocated home addresses, 4,300 bank account-routing pairs, 1,100 mental-health ICD-10 codes (including PTSD flags), 490 undercover designation tags, and 82 senior commanders' unhashed fingerprint minutiae. This information is being used for various malicious activities, such as creating fake IDs (e.g., counterfeit SAPS warrant cards), blackmailing officers using their mental health records, and enabling organised crime groups to identify and target officers or their families. The data was also sold on the dark web in various packages, including 'CommandLayer' for undercover officer details and 'FinanceCore' for banking information."}, {"question": "

What was Polmed's response to the breach and what measures are they taking?

", "answer": "Polmed was alerted to the breach at 03:17 SAST by the ShinyHunters themselves, who demanded a $1 million ransom. Polmed immediately launched 'Operation Javelin' and has approved an emergency budget of R67 million. Their response includes a retainer with Mandiant for incident response, credit-protection and ID-theft cover for all members, dark-web takedown services, hardware-token 2FA for staff, independent penetration testing, and setting aside funds for a class-action lawsuit. They are also implementing forest-wide password resets, disabling legacy NTLM, isolating SQL servers, enforcing Azure AD Conditional Access, planning a full PKI re-roll, and adopting a zero-trust architecture blueprint."}, {"question": "

What are the legal and regulatory implications for Polmed and its third-party providers?

", "answer": "Under POPIA section 19, Polmed is the responsible party and Helios Health Systems (their claims processor) is the operator, both being liable for 'failure to implement reasonable technical and organisational measures.' This could result in an administrative fine of R10 million or 10% of annual turnover. Additionally, disclosing an officer's address is a criminal offense under the SAPS Act s36(2), and the Cybercrimes Act 19 of 2021 outlaws unlawful data acquisition. There's also the potential for a civil class-action lawsuit, with estimates pushing damages past R800 million based on previous precedents."}, {"question": "

Who are ShinyHunters and what are their global connections?

", "answer": "ShinyHunters is a franchise brand of cybercriminals, not a single gang, first noted after the 2020 Tokopedia breach. Microsoft's threat intelligence tracks at least four distinct crews using this handle. The group responsible for the Polmed breach predominantly communicates in Indonesian and reuses Command and Control (C2) domains from previous attacks like Unacademy and BigBasket. Interpol's African Cybercrime desk has linked this crew to job advertisements on dark forums. A parallel FBI investigation suggests the same cell attempted to ransom data from Indonesia's national health scheme in December 2023 before targeting South Africa. South Africa faces challenges in apprehending the culprits due to the lack of an extradition treaty with Indonesia and the complexities of international cybercrime investigations."}]

Isabella Schmidt
Isabella Schmidt

Isabella Schmidt is a Cape Town journalist who chronicles the city’s evolving food culture, from Bo-Kaap spice merchants to Khayelitsha microbreweries. Raised hiking the trails that link Table Mountain to the Cape Flats, she brings the flavours and voices of her hometown to global readers with equal parts rigour and heart.

View all articles →
Share: