SADC attack: cyber-espionage or bid to cover up corruption?

There are fears of a possible far reaching cybersecurity fallout at the SADC Secretariat in Gaborone after six armed men penetrated the secure building’s data hub two weeks ago and stole 22 official laptops.

Although the stolen laptops expose the SADC secretariat to an extensive data breach, which includes theft of passwords, access codes and confidential information, at the time of going to press, this was the least of the secretariat’s worries.

With the burglars having made away with CCTV cameras and footage, this is making it difficult for SADC officials and Botswana Police Service investigators to establish the extent of the security breach and whether there was systemic penetration.

The Commissioner of Police Keabetswe Makgophe is actually personally involved in the investigations. Indications are thatthe situation is actually worse than it may appear at first.

Unconfirmed reports claim that the burglars were able to access the secretariat’s server and may have infected some computers with malware, sparking fears that bad guys may be having persistent, hidden, ongoing access to SADC secretariat’s systems.

Botswana Police Services spokesperson, Assistant Commissioner Dipheko Motube confirmed the attack at the SADC Secretariat, but would not comment on claims that the assailants gained access to the server and may have infected some computers with malware. “I cannot comment on such details as they are the subject of the ongoing investigation”, he told the Sunday Standard.

A source inside the SADC secretariat told the Sunday Standard that  since the burglars managed to break into the Secretariat’s IT floor, there are fears that they may have infected some computers with malware. This would result in systemic penetration, giving the burglars persistent, hidden, ongoing access to SADC secretariat’s systems.

Malware often doesn’t show itself until a set period of time or trigger happens. So machines that seem perfectly fine may well be Trojan horses.

For now, the motive behind the attack is a subject of speculations.

Organizations like SADC are a high-value target for cyber-espionage activity. The actors may have conducted the intrusion with the goal of compromising large numbers of users within the SADC network for further long-term intelligence gathering.

Another theory is that the SADC Secretariat’s network may have been compromised to cover up years of corruption.

RELATED STORIES

Read this week's paper