Skip to content
safemode.space
All incidents
2021-09-06 (approximate)
data exposure

SANSA data-leak claim and South African Department of Justice attack (2021)

Confidence in this reading:
moderate

What happened

On 6 September 2021 the South African National Space Agency (SANSA) was notified of a possible breach of its IT systems, and a group identifying itself as CoomingProject claimed responsibility for publishing SANSA data. SANSA's position, reported on 9 September 2021, is that a file consisting of SANSA information was dumped in the public domain, that its network was not compromised and that no network breach occurred, and that the material came from a public anonymous FTP server at its Hermanus facility and consisted of personal information of previous SANSA students. SANSA stated that takedown requests had been sent to the sites and domains hosting the data while acknowledging the data might still appear elsewhere. On the same day, 6 September 2021, South Africa's Department of Justice and Constitutional Development suffered an IT incident affecting offices and courts nationwide; at the time of the ITWeb report the department had not confirmed whether a cyberattack had occurred. Later reporting indicates neither body received a ransom demand.

Edge-less by curation. SANSA's own account is that there was no network breach and that the exposed material was student personal information sitting on a publicly accessible anonymous FTP server, which is a data-exposure finding rather than an intrusion, and personal data rather than anything with a space nexus. SPARTA cites this incident at REC-0008, and nothing in the retrieved sourcing supports supply-chain reconnaissance or any other technique. The Department of Justice half of the pairing is a genuine and more serious incident, but it concerns a justice ministry rather than a space organisation and has no place in this corpus except as the context that put SANSA in the headline. Two caveats on sourcing: the Daily Maverick reports that SPARTA cites carry a ransomware framing that SANSA's own account, as reported by ITWeb, does not support, and the later of the two is itself the correction to it, so this record follows ITWeb on what happened at SANSA; and a data volume figure circulating in secondary coverage is confirmed by no cited source and is therefore not stated anywhere in this record. Record confidence moved from low to moderate on 2026-08-18 under decisions entry 157, on the reading in docs/audits/2026-08-18-entry-148-confidence-value-audit.md: the account is established and what is missing is not the account. Entry 148 puts the actor and any one mapping outside this axis.

Attack vector

Per SANSA, none against its network: the material is stated to have come from a public anonymous FTP server at the Hermanus facility, with no firewall or network breach. No cited source describes an intrusion mechanism.

Operational impact

None reported at SANSA. At the Department of Justice, information systems were reported unavailable across offices and courts nationwide.

Data compromised

Per SANSA, personal information of previous SANSA students, taken from a publicly accessible anonymous FTP server. No mission, satellite or operational data is reported by any cited source.

Disclosed

2021-09-09

SPARTA techniques evidenced

No SPARTA technique is mapped to this record.

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • The Department of Justice's systems were reported encrypted and unavailable nationwide, the closest thing in this pairing to a ransomware event. Rejected on two independent grounds: the Department of Justice is not a space organisation and does not belong in this corpus, and SPARTA's EX-0010.01 is ransomware executing on a spacecraft.

  • Worth stating explicitly rather than passing over, because SANSA's Hermanus facility is a real ground station site. The exposed asset was a public anonymous FTP server holding student records, not mission ground infrastructure, and no source reports telemetry, payload products or command histories being reached.

  • Rejected twice over. SANSA states there was no network breach and that the material came from a publicly accessible anonymous FTP server, so on the operator's account nothing was taken that was not already reachable; and SPARTA's IMP-0006 concerns data gathered, processed and sent from the victim spacecraft, which student records are not.

  • REC-0008 is about mapping manufacturers, test houses, logistics routes, integrator touchpoints and procurement artefacts. What was exposed, on SANSA's own account, is personal information of previous SANSA students. There is no supply-chain material and no reported adversary reconnaissance of one.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

A source marked contradicting disputes the account above rather than supporting it. It is listed because a reader assessing this record should see it.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.