While the R2 billion cyber theft in Ekurhuleni is no longer front-page news, its underlying causes—graft, mismanagement, and weak oversight—continue to haunt the city’s administration. As part of our series on municipal failures, this analysis revisits Ekurhuleni’s crisis to illustrate how years of neglect and corruption have eroded public trust and crippled service delivery.
By Senior Correspondent
Behind the digital screens of the City of Ekurhuleni’s financial headquarters, a massive digital heist unfolded.
The scandal left the metropolitan municipality facing what its own administrators described as a “digital state of emergency” and a financial loss estimated at up to R2 billion.
Evidence presented before Parliament and by independent forensic auditors revealed this was not a sophisticated cyber-attack from a foreign bunker. Rather, it was a basic breach enabled by administrative neglect, unsecured municipal Wi-Fi networks, and a failure to heed warnings raised nearly a year earlier.

While ordinary residents endured crumbling infrastructure, pothole-riddled roads, and ongoing water and electricity outages, billions of rand in municipal revenue vanished.
However, the true significance of this information technology failure extended far beyond a simple security breach.
Viewed in its entirety, the crisis served as the ultimate proof of a total collapse of governance within the metro. It demonstrated a textbook case of “municipal capture,” where the basic guardrails of administrative integrity, financial oversight, and security were dismantled simultaneously to serve a network of private and criminal interests.
The Car Park Hackers
The heart of the crisis lay within the computerised billing system known as the SOLAR Enterprise Resource Planning system.
This software was the financial engine of the metro, responsible for tracking who owed money for electricity, water, and property rates, and ensuring that those funds were collected to keep public services running.
The physical breach occurred at the municipal Licensing Department in Bedfordview. Forensic investigators confirmed that cybercriminals did not even need to storm through the front doors of the building to access the system. Instead, they parked their motor vehicles in the public car park outside.

Because the municipality had failed to install basic corporate security or encryption on its local Wi-Fi network, the hackers were able to connect to the signal from the comfort of their car seats. They intercepted local digital traffic, planted malicious spyware, and harvested high-level administrative credentials.
Once inside the network, the lack of internal digital borders meant that a breach at a single licensing office gave the hackers total access to the entire metropolitan financial database.
What followed was a systematic manipulation of municipal records.
Operating during a twelve-hour “night shift” window between six o’clock in the evening and six o’clock in the morning—a period when the audit revealed the metro’s cybersecurity monitoring was completely inactive—the criminals went to work.
They wiped out massive outstanding debts for select businesses and individuals, altered billing histories, and unlawfully issued official clearance certificates that falsely declared these accounts to be fully paid.
Nepotism and the Back Door Key
A cyber-attack of this magnitude rarely occurs without a breakdown in institutional oversight. Forensic investigators discovered that external information technology contractors had been granted broad, unrestricted administrative privileges to maintain the billing system.
The municipality had failed to implement a basic protocol that limited what a private contractor could do on state systems. Consequently, these private vendors held the unchecked ability to rewrite financial records without any municipal official needing to sign off on the changes.
This oversight failure was compounded by severe conflicts of interest at the very top of the municipal administration, creating a closed loop of mutual benefit.
A private information technology firm called XET Solutions had been awarded lucrative municipal contracts to maintain, upgrade, and secure the exact billing system that was breached.
A criminal complaint subsequently submitted to the Public Protector exposed that while XET Solutions was receiving these multi-million-rand municipal tenders, the company employed both the son of the former City Manager, Imogen Mashazi, and the daughter of former chief financial officer and municipal official Kagiso Lerutla.
Investigators also uncovered a trail of paper and payments linking the private firm to executive luxury. In July 2022, former City Manager Dr Imogen Mashazi, her husband, and two associates flew to London on a privately chartered jet costing over R3 million.
Financial records traced the payment for this private charter back to a businessman, Ze Nxumalo, the owner of ZIG Holdings. Nxumalo had received a payment of more than R5 million from XET Solutions—the municipal information technology contractor—just before securing the flight.
Shortly after returning from the London trip, the administration led by Mashazi awarded XET Solutions a follow-up contract to continue managing the billing platform, despite the firm extracting nearly R5 million from the metro amid allegations of inflated billing and ghost employee entries.
The Three Pillars of Governance Collapse
To comprehend how such a brazen heist and its associated cover-ups could go undetected for so long, one must look at how the three primary pillars of municipal governance—administrative power, financial control, and security—were systematically compromised.
First, administrative integrity was paralysed by high-level nepotism and the deliberate protection of corrupt actors. When senior executives actively shielded colleagues from scrutiny, the internal machinery of accountability ceased to function. This environment allowed critical oversight roles to be left vacant deliberately.
At the height of the crisis, the municipality suffered an eighty-one per cent vacancy rate in its Supply Chain Management division, leaving the very department tasked with policing tenders entirely unstaffed.
Second, financial control evaporated because the billing system was turned into an open vault. By ignoring forensic warnings regarding the billing software as early as July 2025, administrative leaders allowed the city’s primary revenue source to be manipulated.
Wiping out the debts of large commercial ratepayers starved the city of the liquidity needed to pay bulk utility suppliers such as Eskom and Rand Water, precipitating the broader municipal debt crisis, which now stands at over R10 billion.
Third, and most concerning, municipal security and law enforcement arms were subverted to act as a shield for these activities. While the treasury was being drained electronically, internal accountability was entirely extinguished.
This created a highly hostile environment where any attempt by ethical public servants to audit corrupt contracts or expose internal vulnerabilities was met with severe structural resistance.
What the Role Players Said
The fallout from this digital breakdown and the accompanying administrative collapse drew fierce condemnation from parliamentary oversight bodies, financial watchdogs, and civic organisations.
During parliamentary hearings into the financial collapse of the metro, members of the Standing Committee on Public Accounts (SCOPA) expressed disbelief at how easily the municipality’s primary revenue engine was compromised.
The lawmakers noted that the breach had severely crippled the city’s capacity to collect revenue, compounding a wider municipal debt crisis that currently stands at over R10 billion.
In her evaluation of the municipality’s finances, Auditor-General Tsakani Maluleke handed Ekurhuleni a Qualified Audit Opinion, explicitly pointing out that data within the billing system had been subjected to unauthorised manual adjustments and system overrides.
In her national briefing, Maluleke noted: “Oversight by councils and mayors remains ineffective; controls continue to deteriorate; and non-compliance with legislation is frequently trivialised. Fiscal discipline remains weak, with funds being mismanaged and wasted through deficient procurement practices and poor project planning.”
Political and civic watchdogs were equally scathing.
The Freedom Front Plus, which actively challenged the administration over the breach, released a statement labelling the event a predictable disaster: “This incident of cybercrime is no accident; it is the direct consequence of years of cadre deployment, incompetent appointments, inadequate oversight and an utter lack of accountability under ANC rule. Senior managers and the political leadership should also be held personally accountable for allowing the Metro’s critical systems to be breached so easily.”
Julius Kleynhans, Executive Manager at the civil society group OUTA, emphasised the heavy burden this placed on ordinary members of the public, stating that residents continued to pay the price for weak governance, poor budgeting, procurement failures, and an absolute lack of consequence management.
The Official Response from the Metro
Faced with a mounting financial crisis, the executive leadership of the municipality was forced to account for the massive gaps in its revenue collection.
Ekurhuleni Finance Member of the Mayoral Committee (MMC), Jongizizwe Dlabathi, formally conceded to Parliament that the city had suffered a catastrophic loss in revenue collection following the major system breach.
Dlabathi explained that the municipal treasury only grasped the full scale of the digital heist when they noticed a massive, irreconcilable chasm between the revenue the city was supposed to collect and the actual cash arriving in its bank accounts.
In an official turn of phrase, the municipality officially labelled the situation a “digital state of emergency”.
While the metro claimed it had initiated aggressive “back-billing” processes to reclaim nearly R900 million, the chaotic state of the database meant thousands of ordinary citizens received highly inaccurate, inflated bills as the city desperately tried to patch its self-inflicted financial black hole.
The independent forensic report confirmed that municipal leaders were given detailed warnings about these precise system vulnerabilities as early as July 2025. The failure to act on those warnings for nearly a year allowed an external syndicate, aided by internal collusion, to systematically bleed the municipality dry while the lights went out on the streets of Ekurhuleni.
The Special Investigating Unit Steps In
As the sheer scale of the digital looting became public knowledge by mid-2026, political pressure mounted for direct intervention from national law enforcement.
Political parties, led prominently by ActionSA, formally petitioned the Special Investigating Unit to step in and secure the stolen public funds.
The demands placed before the Special Investigating Unit were twofold.
First, civic and political leaders called for the immediate preservation and seizure of the personal assets belonging to former City Manager Dr Imogen Mashazi, arguing that public funds intended for service delivery were unlawfully diverted to enrich politically connected individuals.

Second, they demanded that the unit freeze all ongoing municipal payments to XET Solutions. Despite the massive security failures, glaring conflicts of interest, and the devastating breach of the billing platform, the private technology firm had shockingly continued to receive business from the city.
Opponents of the administration argued that only through immediate asset recovery and uncompromising accountability by the Special Investigating Unit could the residents of Ekurhuleni hope to see justice for the financial devastation inflicted upon their municipality.
The Ultimate Cost of Truth
The true gravity of this entire saga cannot be measured solely in lost revenue, broken systems, or political statements. The hollowing out of the metro was protected by an enforcement network that extracted the ultimate price from those who refused to look the other way.
In June 2025, Mpho Mafole, a newly appointed Group Divisional Head for Corporate and Forensic Audits in Ekurhuleni, was instructed to conduct a probity audit on the awarding of a massive R1.8 billion mobile chemical toilets contract.

Mafole, who brought over fourteen years of clean auditing experience from the Office of the Auditor-General, compiled a forensic dossier identifying severe, systemic procurement irregularities.
Mafole’s report exposed how legitimate, qualified bidders were unlawfully disqualified while highly favoured, politically connected providers were advanced.
Mafole officially submitted his completed forensic report on the twenty-sixth of June 2025. Just four days later, on the thirtieth of June, after leaving a day-long meeting with municipal officials, he was ambushed while driving along the R23 in Kempton Park. Hitmen fired multiple shots into his vehicle, killing him instantly.
His assassination occurred just days before his findings could trigger a formal Council intervention. It stands as a grim, final testament to the reality of municipal capture in Ekurhuleni: when billions of rand are extracted from the state through compromised digital infrastructure and corrupt tenders, the ultimate cost of accountability is paid in human blood.
The Final Reckoning
The unchecked siphoning of public funds in Ekurhuleni has created an environment akin to a feeding frenzy, where opportunists from within and outside the system circle the city’s resources with increasing boldness.
The sheer scale and visibility of this predation signal not merely administrative failure, but a challenge to the very notion of accountable governance. If left unaddressed, this pattern risks becoming self-reinforcing, drawing in even more actors eager to profit from the city’s vulnerability.
For Ekurhuleni and municipalities like it, the present moment is a critical test: whether the cycle of impunity can be broken before what remains is consumed entirely.
