Tvrdnje o hakiranju MTN-a su uvelike pretjerane, ali hakerski aktivisti neće prestati
U srpnju 2026. godine, hakerska grupa pod nazivom ki4tane tvrdila je da je narušila MTN, glavnog južnoafričkog telekomunikacijskog pružatelja, i objavila navodno ukradene poverljive podatke. Post, dio šire kampanje poznate kao #OpSouthAfrica, uokvirila je kršenje kao političku osvetu protiv tretmana Nigerijskih imigranata i stranih radnika u Južnoj Africi. Kampanja, koju predvode grupe poput Nullsec Nigerije i 404 Crew, ima za cilj izložiti vladine i korporativne neuspjehe putem digitalnog aktivizma. Međutim, istraga koju je proveo Daily Maverick otkrila je da su navodno ukradeni podaci - poput poverljivih podataka "klijenata" i "zaposlenica" - zapravo bili podaci o registraciji za MTN-ove portale za programere i uključivali su povijesne podatke ili testove. MTN je mirno odgovorio, navodeći da kršenje ne ukazuje na kompromitiranje novog sustava, sugerišući da je to bio još jedan pokušaj digitalne osvete, a ne pravi sigurnosni problem.
A threat actor known as ki4tane posted a message on the Breached hacker forum on Sunday, 26 July 2026, claiming to have accessed a large amount of data from MTN, a major telecommunications provider in South Africa. The post, titled “MTN BREACHED,” included the official MTN yellow logo and alleged that hundreds of customer credentials and around 2,000 employee login details were exposed. The attacker framed the breach as a form of political retaliation, accusing MTN of exploiting customers' money due to ongoing tensions between South Africa and Nigeria. The incident marks another move in the #OpSouthAfrica campaign, a hacktivist initiative led by groups such as Nullsec Nigeria, also known as Anonymous Nigeria, 404 Crew, and Infernalis. This campaign emerged in response to anti-immigration protests and xenophobic violence against Nigerian nationals and other foreign workers in South African cities earlier in May 2026. These groups have previously targeted various South African state institutions, including the South African Civil Aviation Authority, the National Space Agency, Sassa, and the Department of Correctional Services. Nullsec Nigeria's stated objective is to expose governmental and corporate shortcomings to pressure the South African government to cease its anti-foreigner policies. Unlike traditional cybercriminal organizations, their focus lies in political activism and digital retribution rather than financial gain through ransomware or direct extortion. The group has used similar tactics in past operations, often leveraging public outrage to justify their actions. Daily Maverick received information about the post from Dark Notify, a dark web research collective. They also obtained samples of the supposedly stolen data. Upon closer examination, the leaked files did not support the threat actor’s claims. For example, the files labeled client.txt and client.emails.txt contained registration credentials for MTN’s developer portals, specifically developers.mtn.com, momodeveloper.mtn.com, and hsdpportal.mtn.com, rather than customer billing accounts or mobile money wallet details. Similarly, the employee credential files appeared questionable. While they included numerous login entries primarily ending in @mtn.com or structured as domain accounts like MTNGroupsa\xxx, these credentials were likely historical, duplicate, or test data. This suggests that the data might not represent a recent breach but could instead stem from older incidents. MTN responded to the claims after being informed by Daily Maverick. The company stated that it was aware of the allegations but emphasized that the materials shared did not indicate a new system compromise. MTN reiterated its commitment to protecting customer information and noted that it regularly monitors its systems for potential threats. In 2025, MTN faced a cybersecurity incident involving a legacy environment slated for migration to a new fully managed domain. Before the migration was complete, the data was compromised, affecting a logging server that collected data from several operating companies. The company swiftly removed the compromised server within 48 hours, notified regulatory bodies, and initiated a comprehensive internal review. This process led to a two-year cybersecurity improvement program, expected to conclude in 2026. Considering that the current data appears largely historical, test-related, or tied to developer access, it is plausible that the files circulating online are remnants from the 2025 breach rather than evidence of a fresh intrusion. This aligns with MTN’s assertion that no new compromise has occurred. As the hacktivist movement continues, it remains unclear whether further actions will follow or if the situation will stabilize.
Kako je izvijestila svaka strana
Isti događaj, grupiran prema političkom nagibu medija koji su o njemu izvještavali.
progresivno
sredina
konzervativno
★
Kako je izvijestila svaka strana
Podržite neovisne vijesti svjesne pristranosti i otključajte društveni puls, glasovanje zajednice i svoj personalizirani feed Za tebe.
U srpnju 2026. godine, hakerska grupa pod nazivom ki4tane tvrdila je da je narušila MTN, glavnog južnoafričkog telekomunikacijskog pružatelja, i objavila navodno ukradene poverljive podatke. Post, dio šire kampanje poznate kao #OpSouthAfrica, uokvirila je kršenje kao političku osvetu protiv tretmana Nigerijskih imigranata i stranih radnika u Južnoj Africi. Kampanja, koju predvode grupe poput Nullsec Nigerije i 404 Crew, ima za cilj izložiti vladine i korporativne neuspjehe putem digitalnog aktivizma. Međutim, istraga koju je proveo Daily Maverick otkrila je da su navodno ukradeni podaci - poput poverljivih podataka "klijenata" i "zaposlenica" - zapravo bili podaci o registraciji za MTN-ove portale za programere i uključivali su povijesne podatke ili testove. MTN je mirno odgovorio, navodeći da kršenje ne ukazuje na kompromitiranje novog sustava, sugerišući da je to bio još jedan pokušaj digitalne osvete, a ne pravi sigurnosni problem.
Procjena pristranosti (Progresivno): U članku se prikazuje hakerska kampanja kao politički motivirana odmazda protiv ksenofobičnih politika, u skladu s lijevom perspektivom koja kritizira sustavni rasizam i ksenofobiju.
★
Neka vijesti ostanu poštene.
ObjectiveNews financiraju čitatelji i bez oglasa je – pristranost vam pokazujemo, ne skrivamo. Podržite neovisno novinarstvo za 5 €/mjesec.