<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybercrimes Act Archives - ProtectionWeb</title>
	<atom:link href="https://www.protectionweb.co.za/tag/cybercrimes-act/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.protectionweb.co.za/tag/cybercrimes-act/</link>
	<description>First with Security News</description>
	<lastBuildDate>Wed, 11 Jun 2025 11:14:44 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://www.protectionweb.co.za/wp-content/uploads/2024/04/cropped-ProtectionWebLogo-512x512-1-32x32.png</url>
	<title>Cybercrimes Act Archives - ProtectionWeb</title>
	<link>https://www.protectionweb.co.za/tag/cybercrimes-act/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Landmark cybercrime conviction: Former IT employee sentenced to eight years for fraud and extortion plot</title>
		<link>https://www.protectionweb.co.za/cyber-security/cybercrime-conviction-former-it-employee-sentenced-to-eight-years-for-fraud-and-extortion-plot/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Wed, 11 Jun 2025 06:10:22 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cybercrimes Act]]></category>
		<category><![CDATA[Ecentric]]></category>
		<category><![CDATA[Lucky Majangandile Erasmus]]></category>
		<category><![CDATA[SAPS]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98008</guid>

					<description><![CDATA[<p>Lucky Majangandile Erasmus (36) was sentenced to eight years’ imprisonment on Monday, 3 June 2025, by the Specialised Commercial Crimes Court in connection with a high-profile cybercrime case targeting South African fintech company, Ecentric. The sentence follows a plea agreement entered into with the State. Three years of the eight-year sentence were suspended for five [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/cybercrime-conviction-former-it-employee-sentenced-to-eight-years-for-fraud-and-extortion-plot/">Landmark cybercrime conviction: Former IT employee sentenced to eight years for fraud and extortion plot</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="101" data-end="569">Lucky Majangandile Erasmus (36) was sentenced to eight years’ imprisonment on Monday, 3 June 2025, by the Specialised Commercial Crimes Court in connection with a high-profile cybercrime case targeting South African fintech company, Ecentric. The sentence follows a plea agreement entered into with the State. Three years of the eight-year sentence were suspended for five years, meaning Erasmus will serve an effective five years in prison.</p>
<p data-start="571" data-end="941">The charges against Erasmus relate to a 2023 incident in which he and co-accused Felix Unathi Pupu (43), both former employees of Ecentric, installed software on the company’s systems that enabled unauthorized remote access. This access was later exploited in an attempted ransomware scheme that included multiple extortion attempts and led to significant data breaches.</p>
<p data-start="943" data-end="1003">Erasmus was convicted on a wide range of charges, including:</p>
<ul data-start="1005" data-end="1529">
<li data-start="1005" data-end="1083">
<p data-start="1007" data-end="1083">One count of contravening section 12 of the Cybercrimes Act No. 19 of 2020</p>
</li>
<li data-start="1084" data-end="1114">
<p data-start="1086" data-end="1114">One count of theft of data</p>
</li>
<li data-start="1115" data-end="1158">
<p data-start="1117" data-end="1158">Two counts of attempted cyber extortion</p>
</li>
<li data-start="1159" data-end="1189">
<p data-start="1161" data-end="1189">Four counts of cyber fraud</p>
</li>
<li data-start="1190" data-end="1245">
<p data-start="1192" data-end="1245">Four counts of unlawful access to a computer system</p>
</li>
<li data-start="1246" data-end="1315">
<p data-start="1248" data-end="1315">Three counts involving unlawful use of software or hardware tools</p>
</li>
<li data-start="1316" data-end="1376">
<p data-start="1318" data-end="1376">Two counts of unlawful interference with network or data</p>
</li>
<li data-start="1377" data-end="1433">
<p data-start="1379" data-end="1433">One count of interference with a data storage medium</p>
</li>
<li data-start="1434" data-end="1469">
<p data-start="1436" data-end="1469">One count of password resetting</p>
</li>
<li data-start="1470" data-end="1502">
<p data-start="1472" data-end="1502">One count of unlawful access</p>
</li>
<li data-start="1503" data-end="1529">
<p data-start="1505" data-end="1529">One count of trespassing</p>
</li>
</ul>
<p data-start="1531" data-end="1992">According to court documents, the software installed by the accused allowed a third party to breach Ecentric’s IT infrastructure. On 14 November 2023, a ransom demand was made to Ecentric’s CEO, requesting payment of US$534,260 within 16 hours, with the threat that company data would be leaked publicly—including to competitors and regulators—within 30 hours. When the initial demand was not met, a second ransom of US$1 million was issued on 30 November 2023.</p>
<p data-start="1994" data-end="2154">Ecentric did not comply with either demand. However, four of its retail clients sustained financial losses totalling R794,808.51 as a result of the cyberattack.</p>
<p data-start="2156" data-end="2331">Erasmus has been in custody since 14 December 2023. His co-accused, Felix Pupu, remains in custody and is scheduled to appear in court on 30 June 2025 for plea and sentencing.</p>
<p data-start="2333" data-end="2604">As part of the conditions tied to the suspended portion of his sentence, Erasmus must not commit any further offences relating to fraud, cybercrime, or trespassing during the five-year suspension period. A violation would lead to the activation of the suspended sentence.</p>
<p data-start="2606" data-end="2665">The court also declared Erasmus unfit to possess a firearm.</p>
<p data-start="2667" data-end="2856" data-is-last-node="" data-is-only-node="">This case marks a significant application of South Africa’s Cybercrimes Act and highlights the growing focus on criminal accountability for cybersecurity breaches involving insider threats.</p>
<p data-start="2667" data-end="2856" data-is-last-node="" data-is-only-node="">Ecentric welcomed the court’s decision, confirming Erasmus’s conviction and sentencing. Digital forensics firm Cyanre, which assisted in the investigation, praised the outcome, calling it a milestone in South Africa’s fight against cybercrime. The company lauded the collaboration between law enforcement and legal experts, highlighting the success as a testament to the Cyber Crimes Act’s effectiveness.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/cybercrime-conviction-former-it-employee-sentenced-to-eight-years-for-fraud-and-extortion-plot/">Landmark cybercrime conviction: Former IT employee sentenced to eight years for fraud and extortion plot</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Understanding your rights and obligations under the Cybercrimes Act: An integral aspect of businesses&#8217; data and information protection processes</title>
		<link>https://www.protectionweb.co.za/cyber-security/understanding-your-rights-and-obligations-under-the-cybercrimes-act-an-integral-aspect-of-businesses-data-and-information-protection-processes/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Tue, 14 Jan 2025 06:30:32 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cybercrimes Act]]></category>
		<category><![CDATA[South Africa]]></category>
		<category><![CDATA[TS Communications]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=96459</guid>

					<description><![CDATA[<p>The Cybercrimes Act 19 of 2020 (the Cybercrimes Act) is the first statute in South Africa to explicitly recognise cybercrimes by creating a new category of criminal offences under South African law. These cybercrimes include: ·             the unlawful interception of data; ·             the theft of incorporeal property; ·             cyber fraud; ·             cyber forgery and uttering; ·             cyber extortion; ·             the unlawful [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/understanding-your-rights-and-obligations-under-the-cybercrimes-act-an-integral-aspect-of-businesses-data-and-information-protection-processes/">Understanding your rights and obligations under the Cybercrimes Act: An integral aspect of businesses&#8217; data and information protection processes</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-olk-copy-source="MessageBody">The Cybercrimes Act 19 of 2020 (the Cybercrimes Act) is the first statute in South Africa to explicitly recognise cybercrimes by creating a new category of criminal offences under South African law. These cybercrimes include:<u></u><u></u></span></p>
<p><u></u>·             <u></u>the unlawful interception of data;<u></u><u></u></p>
<p><u></u>·             <u></u>the theft of incorporeal property;<u></u><u></u></p>
<p><u></u>·             <u></u>cyber fraud;<u></u><u></u></p>
<p><u></u>·             <u></u>cyber forgery and uttering;<u></u><u></u></p>
<p><u></u>·             <u></u>cyber extortion;<u></u><u></u></p>
<p><u></u>·             <u></u>the unlawful acquisition, possession, provision, receipt or use of a password,       access code or similar data or device;<u></u><u></u></p>
<p><u></u>·             <u></u>unlawfully accessing a computer system or computer data storage medium; and<u></u><u></u></p>
<p><u></u>·             <u></u>the unlawful interference with data, a computer programme, a computer data storage medium or a computer system.<u></u><u></u><u></u></p>
<p>The Cybercrimes Act also places certain obligations on institutions and corporations to comply with stringent security requirements in managing the data of citizens and employees. <span lang="en-GB">Contravention of the </span>Cybercrimes <span lang="en-GB">Act may, upon conviction, result in several </span>penalties<span lang="en-GB">, including fines and up to 15 years imprisonment.<u></u><u></u></span><u></u></p>
<p>Various key sections of the Cybercrimes Act took effect on 1 December 2021. Businesses are increasingly relying on the Cybercrimes Act to enforce their rights to their proprietary information and data.<u></u><u></u><u></u></p>
<p><span lang="en-GB">Recently, a South African airline exercised its rights under the </span>Cybercrimes <span lang="en-GB">Act against a former employee accused of engaging in industrial espionage and misappropriation of the airline’s incorporeal property. The airline filed a complaint in terms of the Cybercrimes Act with the South African Police Service. The airline alleged that the former employee disclosed its confidential information obtained during the employee&#8217;s tenure with the airline, to the employee’s new employer without authorisation.<u></u><u></u></span></p>
<p><span lang="en-GB">Among other things, the employee was accused of unlawfully disseminating copies of documents containing client revenues, thereby violating the confidentiality and proprietary interests of their former employer.<u></u><u></u></span><u></u></p>
<p>Businesses should not only have regard to the protections and possible remedies the Cybercrimes Act offers them, but also to their own obligations under the statute.<u></u><u></u><u></u></p>
<p>Importantly, electronic communications service providers and financial institutions have specific duties in relation to reporting cybercrimes (although these obligations have been suspended until a date to be determined by the President). In terms of section 54, electronic communications service providers and financial institutions must report any cybercrime involving their electronic communications service or network to the <span lang="en-GB">Information Regulator and the South African Police Service </span>within <u>72 hours</u> of becoming aware of the offence. Any information which may be of assistance to <span lang="en-GB">the South African Police Service </span>in conducting their investigation must also be preserved. A failure to comply with these obligations may upon conviction attract a fine of up to R50 000.<u></u><u></u><u></u></p>
<p>According to a directive published by the South African Reserve Bank (SARB), effective August 2024, participants in the National Payment System also have certain duties in relation to reporting cybercrimes.<b> </b><span lang="en-GB">The directive introduces new cyber-security requirements for payment institutions regulated under the National Payment System Act 78 of 1998, including clearing system participants, settlement system participants, third-party payment providers, system operators, payment clearing house system operators, and the operators of payment system financial market infrastructures.<u></u><u></u></span></p>
<p><span lang="en-GB">Notably, </span>payment<span lang="en-GB"> institutions and operators must report material cyber-incidents to the </span>SARB<span lang="en-GB"> within <u>24 hours</u> of the cyber-incident occurring and must submit a report to the SARB containing specified information regarding the cyber-incident within <u>48 hours</u> of the cyber-incident occurring. Payment institutions and operators are also required to provide ongoing updates to the SARB until the incident is fully resolved. As part of their internal business processes, payment institutions and operators must also ensure that any information-sharing arrangements they enter into comply with the relevant provisions of the Cybercrimes Act relating to the disclosure of information.<u></u><u></u></span></p>
<p><span lang="en-GB">Other legislation, such as the Financial Intelligence Centre Act 38 of 2001 and the Prevention and Combatting of Corrupt Activities Act 12 of 2004, also imposes mandatory reporting obligations and it is vital that businesses are aware of their obligations to notify authorities of certain events and offences.</span></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/understanding-your-rights-and-obligations-under-the-cybercrimes-act-an-integral-aspect-of-businesses-data-and-information-protection-processes/">Understanding your rights and obligations under the Cybercrimes Act: An integral aspect of businesses&#8217; data and information protection processes</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
