DIGITAL RETRIBUTION: Claims of an MTN hack have been greatly exaggerated, but the hacktivists won’t stop
In July 2026, a hacktivist group called ki4tane claimed to have breached MTN, a major South African telecommunications provider, and released alleged stolen credentials. The post, part of a broader campaign known as #OpSouthAfrica, framed the breach as political retaliation against South Africa's treatment of Nigerian immigrants and foreign workers. The campaign, led by groups such as Nullsec Nigeria and 404 Crew, aims to expose government and corporate failures through digital activism. However, an investigation by Daily Maverick revealed that the purportedly stolen data—such as 'client' and 'employee' credentials—were actually registration details for MTN's developer portals and included historical or test data. MTN responded calmly, stating that the breach did not indicate a new system compromise, suggesting the incident was another attempt at digital retaliation rather than a genuine security issue.
A threat actor known as ki4tane posted a message on the Breached hacker forum on Sunday, 26 July 2026, claiming to have accessed a large amount of data from MTN, a major telecommunications provider in South Africa. The post, titled “MTN BREACHED,” included the official MTN yellow logo and alleged that hundreds of customer credentials and around 2,000 employee login details were exposed. The attacker framed the breach as a form of political retaliation, accusing MTN of exploiting customers' money due to ongoing tensions between South Africa and Nigeria. The incident marks another move in the #OpSouthAfrica campaign, a hacktivist initiative led by groups such as Nullsec Nigeria, also known as Anonymous Nigeria, 404 Crew, and Infernalis. This campaign emerged in response to anti-immigration protests and xenophobic violence against Nigerian nationals and other foreign workers in South African cities earlier in May 2026. These groups have previously targeted various South African state institutions, including the South African Civil Aviation Authority, the National Space Agency, Sassa, and the Department of Correctional Services. Nullsec Nigeria's stated objective is to expose governmental and corporate shortcomings to pressure the South African government to cease its anti-foreigner policies. Unlike traditional cybercriminal organizations, their focus lies in political activism and digital retribution rather than financial gain through ransomware or direct extortion. The group has used similar tactics in past operations, often leveraging public outrage to justify their actions. Daily Maverick received information about the post from Dark Notify, a dark web research collective. They also obtained samples of the supposedly stolen data. Upon closer examination, the leaked files did not support the threat actor’s claims. For example, the files labeled client.txt and client.emails.txt contained registration credentials for MTN’s developer portals, specifically developers.mtn.com, momodeveloper.mtn.com, and hsdpportal.mtn.com, rather than customer billing accounts or mobile money wallet details. Similarly, the employee credential files appeared questionable. While they included numerous login entries primarily ending in @mtn.com or structured as domain accounts like MTNGroupsa\xxx, these credentials were likely historical, duplicate, or test data. This suggests that the data might not represent a recent breach but could instead stem from older incidents. MTN responded to the claims after being informed by Daily Maverick. The company stated that it was aware of the allegations but emphasized that the materials shared did not indicate a new system compromise. MTN reiterated its commitment to protecting customer information and noted that it regularly monitors its systems for potential threats. In 2025, MTN faced a cybersecurity incident involving a legacy environment slated for migration to a new fully managed domain. Before the migration was complete, the data was compromised, affecting a logging server that collected data from several operating companies. The company swiftly removed the compromised server within 48 hours, notified regulatory bodies, and initiated a comprehensive internal review. This process led to a two-year cybersecurity improvement program, expected to conclude in 2026. Considering that the current data appears largely historical, test-related, or tied to developer access, it is plausible that the files circulating online are remnants from the 2025 breach rather than evidence of a fresh intrusion. This aligns with MTN’s assertion that no new compromise has occurred. As the hacktivist movement continues, it remains unclear whether further actions will follow or if the situation will stabilize.
How each side covered it
The same event, grouped by the political lean of the outlets covering it.
progressive
center
conservative
★
How each side covered it
Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.
In July 2026, a hacktivist group called ki4tane claimed to have breached MTN, a major South African telecommunications provider, and released alleged stolen credentials. The post, part of a broader campaign known as #OpSouthAfrica, framed the breach as political retaliation against South Africa's treatment of Nigerian immigrants and foreign workers. The campaign, led by groups such as Nullsec Nigeria and 404 Crew, aims to expose government and corporate failures through digital activism. However, an investigation by Daily Maverick revealed that the purportedly stolen data—such as 'client' and 'employee' credentials—were actually registration details for MTN's developer portals and included historical or test data. MTN responded calmly, stating that the breach did not indicate a new system compromise, suggesting the incident was another attempt at digital retaliation rather than a genuine security issue.
Bias read (Progressive): The article frames the hacktivist campaign as politically motivated retaliation against xenophobic policies, aligning with left-leaning perspectives that critique systemic racism and xenophobia. While the article presents factual analysis of the breach, it emphasizes the political context and intent
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.