South Africa’s governing African National Congress (ANC) is facing renewed scrutiny after a hacker group claimed to have released a large database containing the personal information of millions of party members, including senior political figures.
The group, known as Black X, recently published nearly 2GB of data on the dark web, alleging that the files contain information linked to approximately 2.3 million ANC members.
While the authenticity of the entire dataset has not been independently verified, reports indicate that several prominent political leaders are allegedly listed among the records.
Senior Political Figures Reportedly Included
According to reports reviewing the leaked material, names associated with President Cyril Ramaphosa, Deputy President Paul Mashatile and Gauteng Premier Panyaza Lesufi appear within the dataset.
Other high-profile figures allegedly represented include Communications Portfolio Committee Chairperson Khusela Diko, Mineral Resources Minister Gwede Mantashe, Trade and Industry Minister Parks Tau, Minister in the Presidency Khumbudzo Ntshavheni and ANC Deputy Secretary-General Nomvula Mokonyane.
The records reportedly contain personal details such as names, identity numbers, mobile phone numbers, email addresses and physical addresses.
The ANC had not publicly commented on the latest publication of the data at the time of reporting.
The alleged leak follows claims made by Black X in August 2025 that it had gained access to the ANC’s membership management platform. At the time, the group reportedly attempted to sell access credentials linked to the database before later releasing passwords that unlocked the files.
Investigation and Regulatory Scrutiny Continue
The ANC previously stated that it had launched an investigation through its ICT service provider, Emperio.
According to the party, preliminary investigations found no conclusive evidence that the production database managed by Emperio had been compromised through unauthorised access.
ANC officials suggested that the incident could involve historical data exposure predating Emperio’s involvement rather than a confirmed breach of the current system.
Documentation released by the party earlier this year indicated that Emperio was still finalising its service-level agreement with the ANC during April 2026. This timeline aligns with claims that any potential compromise may have occurred before the company assumed responsibility for the platform.
The party also acknowledged ongoing technical challenges affecting its Membership Management System, including data inconsistencies, membership record discrepancies and administrative difficulties.
Since then, additional security measures have reportedly been implemented, including reviews of remote access permissions, database security controls and system monitoring processes.
The Information Regulator of South Africa has also become involved in assessing the matter.
According to statements from the regulator, the ANC has not yet formally reported a confirmed security compromise under Section 22 of the Protection of Personal Information Act (POPIA). However, the party has submitted information to the regulator, which is currently being evaluated.
Authorities have not yet confirmed whether the leaked information is authentic, complete or directly linked to an unauthorised intrusion.
If verified, the incident could rank among the most significant political data exposure events in South Africa in recent years, highlighting the growing importance of cybersecurity and personal information protection within political organisations.
Source: MyBroadband, ANC statements, Information Regulator of South Africa.
