Namfisa was hacked
Namfisa was hacked

Namfisa was hacked

It is alleged that neither the Namfisa board nor the forensic investigating team thought it prudent to properly investigate security breaches at the regulator.
Catherine Sasman
The erstwhile board of the Namibia Financial Institutions Supervisory Authority (Namfisa) is accused of having been involved in a “concerted effort and powerful drive” to protect “certain corrupt individuals” and practices during its tenure in 2009.

This accusation is made in an affidavit by the Public Accountants' and Auditors' Board (PAAB) in its court challenge against chartered accountant Hans Hashagen.

The Namfisa board was then under the chairpersonship of Rick Kukuri. Other board members were Baronice Hans (deputy chairperson, who resigned from the board in April 2009), Iipumbu Shiimi (current governor of the Bank of Namibia), Tia Chata and Titus Iipumbu.

In February 2009 the board allegedly instructed the termination of the services of a forensic investigator. It is also accused of having “purposefully” discarded crucial evidence gathered by the investigator.

This evidence included security system files that had been purposely deleted.

At the time, the IT service provider to Namfisa was a company called SALT, of which the board chairperson was Tega Shiimi ya Shiimi.

Ya Shiimi at the time was also the managing director of Sanlam Investment Manager (SIM), as well as a director at Sanlam.

Both Sanlam and SIM are regulated by Namfisa, which is the watchdog of the non-banking financial sector.

Important to note is that SIM at the time facilitated the bulk of the transactions on behalf of the Government Institutions Pension Fund's (GIPF) Development Capital Portfolio (DCP) investment loans that saw the GIPF losing hundreds of millions of dollars.

These transactions at the time were being investigated by Namfisa under the leadership of its former CEO, Rainer Ritter.

It is alleged that on 27 October 2008 an employee of SALT, Chris Baisako, had sent an email to Namfisa's IT manager, Petrus Kafidi. The email contained screenshots of emails received and sent by Namfisa managers and senior employees.

These senior managers and line managers were Ritter, Lily Brandt (general manager of finance and administration), Ebben Kalondo (communications manager), John Uusiku (former manager of the pensions fund department) and Adrianus Vugs (manager: risk and policy).

Ernst & Young and Hashagen's forensic report into alleged misconduct at Namfisa stated that Brandt and Kafidi were asked to look into these emails.

EY's conclusion on the matter was that the screenshots allegedly found on Kafidi's computer could be explained by Brandt and Kafidi and that it seemed to have been “within the ambit” of Kafidi's duties.

The EY report did not mention the service and confidentiality agreement between Namfisa and SALT, and no information was sought from Baisako on why he had accessed emails of the regulatory body.

Also questioned is how the EY report could conclude that “snooping” into senior managers' email correspondence could be regarded as within the ambit of the IT manager's duties.

Furthermore, SALT's interest in the internal email correspondence between the senior Namfisa staff remained unanswered.

Neither was it explained what authority Brand had to allow SALT to intercept, copy or distribute internal emails of senior staff, since she was not concerned with regulatory investigations.



The EY investigating team is said to have had all the information pertaining to this, and other, matters, yet it allegedly failed to properly report or investigate these, the result of which was Ritter's eventual exit from Namfisa.







BACKGROUND



Prior to the EY forensic investigation, Ritter had given two reports to the Namfisa board that pertained to security issues experienced on the Namfisa premises during 24 hours in November 2008.



These reports alleged that between 15:30 on 12 November 2008 and 08:00 on 13 November 2008 the Namfisa forensic IT server was hacked and data relating to two investigations the regulator was conducting was likely removed.



The reports said it was likely that other files had also been removed because a removable device containing critical data was destroyed.



It stated that five databases were probably copied from the server and access privileges had been changed on the rest of the system.







SEQUENCE OF EVENTS



The report to the Namfisa board stated that on 12 November 2008 at around 15:30 the network became “completely inoperable” on a large section of the first floor and the forensics room at Namfisa's premises in the Sanlam building.



At the time Kafidi allegedly could not be reached by telephone.



At about 08:00 on 14 November 2008 it was discovered that the server software was inoperable and the hacking was revealed.



It was then recommended that Namfisa should get higher-level physical and logistical security and more secure locking systems for the forensic room.



Already by July 2008 it had been observed that the Namfisa network and computing system could have been accessed from outside with minimal effort. In short, the Namfisa network was found to have been insecure and open to the world.



A report in December 2008 said SALT, an external organisation, was managing an email server and that all emails were compromised and harvested for at least seven months.



It is alleged that SALT at some point had removed all security barriers between Namfisa and SALT, which effectively exposed Namfisa to other SALT clients and the entire world.



At the time, a high level of outward data traffic from personal computers was observed via data mining software “planted” on the computers while the network was compromised.

CATHERINE SASMAN

Comments

Namibian Sun 2024-05-06

No comments have been left on this article

Please login to leave a comment

Premier League: Liverpool 4 vs 2 Tottenham Hotspur | Brighton 1 vs 0 Aston Villa | Chelsea 5 vs 0 West Ham | Manchester City 5 vs 1 Wolves | Brentford 0 vs 0 Fulham | Sheffield United 1 vs 3 Nottingham Forest | Burnley 1 vs 4 Newcastle | Arsenal 3 vs 0 Bournemouth | Luton Town 1 vs 1 Everton LaLiga: Rayo Vallecano 0 vs 1 Almería | Sevilla 3 vs 0 Granada | Valencia 0 vs 1 Deportivo Alaves | Celta Vigo 3 vs 2 Villarreal | Osasuna 0 vs 2 Real Betis | Mallorca 0 vs 1 Atletico Madrid | Girona 4 vs 2 Barcelona | Real Madrid 3 vs 0 Cadiz | Real Sociedad 2 vs 0 Las Palmas | Getafe 0 vs 2 Athletic Club SerieA: AS Roma 1 vs 1 Juventus | AC Milan 3 vs 3 Genoa | Empoli 0 vs 0 Frosinone | Hellas Verona 2 vs 1 Fiorentina | Cagliari 1 vs 1 Lecce | Sassuolo 1 vs 0 Inter Milan | Monza 2 vs 2 SS Lazio | Torino 0 vs 0 Bologna European Championships Qualifying: Plymouth Argyle 1 vs 0 Hull City | Birmingham City 1 vs 0 Norwich City | Coventry City 1 vs 2 Queens Park Rangers | Stoke City 4 vs 0 Bristol City | Swansea City 0 vs 1 Millwall FC | Leeds United 1 vs 2 Southampton | Ipswich Town 2 vs 0 Huddersfield Town | Sunderland 0 vs 2 Sheffield Wednesday | Rotherham United 5 vs 2 Cardiff City | Middlesbrough 3 vs 1 Watford | Leicester City 0 vs 2 Blackburn Rovers | West Bromwich Albion 3 vs 0 Preston North End English Championship: Plymouth Argyle 1 vs 0 Hull City | Birmingham City 1 vs 0 Norwich City | Coventry City 1 vs 2 Queens Park Rangers | Stoke City 4 vs 0 Bristol City | Swansea City 0 vs 1 Millwall FC | Leeds United 1 vs 2 Southampton | Ipswich Town 2 vs 0 Huddersfield Town | Sunderland 0 vs 2 Sheffield Wednesday | Rotherham United 5 vs 2 Cardiff City | Middlesbrough 3 vs 1 Watford | Leicester City 0 vs 2 Blackburn Rovers | West Bromwich Albion 3 vs 0 Preston North End Katima Mulilo: 18° | 35° Rundu: 16° | 34° Eenhana: 14° | 34° Oshakati: 17° | 33° Ruacana: 16° | 33° Tsumeb: 17° | 32° Otjiwarongo: 14° | 30° Omaruru: 15° | 32° Windhoek: 13° | 28° Gobabis: 16° | 29° Henties Bay: 13° | 19° Wind speed: 19km/h, Wind direction: S, Low tide: 08:09, High tide: 14:30, Low Tide: 20:18, High tide: 02:00 Swakopmund: 15° | 17° Wind speed: 20km/h, Wind direction: SW, Low tide: 08:07, High tide: 14:28, Low Tide: 20:16, High tide: 02:00 Walvis Bay: 14° | 21° Wind speed: 25km/h, Wind direction: SW, Low tide: 08:07, High tide: 14:27, Low Tide: 20:16, High tide: 02:00 Rehoboth: 15° | 29° Mariental: 16° | 31° Keetmanshoop: 17° | 31° Aranos: 18° | 31° Lüderitz: 13° | 22° Ariamsvlei: 17° | 34° Oranjemund: 12° | 20° Luanda: 25° | 29° Gaborone: 15° | 30° Lubumbashi: 16° | 27° Mbabane: 14° | 28° Maseru: 10° | 25° Antananarivo: 10° | 22° Lilongwe: 17° | 29° Maputo: 18° | 30° Windhoek: 13° | 28° Cape Town: 15° | 16° Durban: 18° | 29° Johannesburg: 16° | 25° Dar es Salaam: 22° | 30° Lusaka: 19° | 30° Harare: 14° | 29° Currency: GBP to NAD 23.09 | EUR to NAD 19.82 | CNY to NAD 2.55 | USD to NAD 18.39 | DZD to NAD 0.14 | AOA to NAD 0.02 | BWP to NAD 1.31 | EGP to NAD 0.38 | KES to NAD 0.14 | NGN to NAD 0.01 | ZMW to NAD 0.67 | ZWL to NAD 0.04 | BRL to NAD 3.64 | RUB to NAD 0.2 | INR to NAD 0.22 | USD to DZD 134.19 | USD to AOA 834.06 | USD to BWP 13.62 | USD to EGP 47.9 | USD to KES 133.48 | USD to NGN 1380 | USD to ZAR 18.4 | USD to ZMW 27.1 | USD to ZWL 321 | Stock Exchange: JSE All Share Index 76428.31 Up +0.50% | Namibian Stock Exchange (NSX) Overall Index 1700.24 Up +0.45% | Casablanca Stock Exchange (CSE) MASI 13403.47 Up +0.61% | Egyptian Exchange (EGX) 30 Index 26113.71 Up +3.34% | Botswana Stock Exchange (BSE) DCI Same 0 | NSX: MTC 7.75 SAME | Anirep 8.99 SAME | Capricorn Investment group 17.34 SAME | FirstRand Namibia Ltd 49 DOWN 0.50% | Letshego Holdings (Namibia) Ltd 4.1 UP 2.50% | Namibia Asset Management Ltd 0.7 SAME | Namibia Breweries Ltd 31.49 UP 0.03% | Nictus Holdings - Nam 2.22 SAME | Oryx Properties Ltd 12.1 UP 1.70% | Paratus Namibia Holdings 11.99 SAME | SBN Holdings 8.45 SAME | Trustco Group Holdings Ltd 0.48 SAME | B2Gold Corporation 47.34 DOWN 1.50% | Local Index closed 677.62 UP 0.12% | Overall Index closed 1534.6 DOWN 0.05% | Osino Resources Corp 19.47 DOWN 2.41% | Commodities: Gold US$ 2 323.63/OZ UP +0.95% | Copper US$ 4.58/lb UP +1.12% | Zinc US$ 2 924.30/T DOWN -0.08% | Brent Crude Oil US$ 84.20/BBP UP +0.85% | Platinum US$ 959.56/OZ UP +0.39% Sport results: Premier League: Liverpool 4 vs 2 Tottenham Hotspur | Brighton 1 vs 0 Aston Villa | Chelsea 5 vs 0 West Ham | Manchester City 5 vs 1 Wolves | Brentford 0 vs 0 Fulham | Sheffield United 1 vs 3 Nottingham Forest | Burnley 1 vs 4 Newcastle | Arsenal 3 vs 0 Bournemouth | Luton Town 1 vs 1 Everton LaLiga: Rayo Vallecano 0 vs 1 Almería | Sevilla 3 vs 0 Granada | Valencia 0 vs 1 Deportivo Alaves | Celta Vigo 3 vs 2 Villarreal | Osasuna 0 vs 2 Real Betis | Mallorca 0 vs 1 Atletico Madrid | Girona 4 vs 2 Barcelona | Real Madrid 3 vs 0 Cadiz | Real Sociedad 2 vs 0 Las Palmas | Getafe 0 vs 2 Athletic Club SerieA: AS Roma 1 vs 1 Juventus | AC Milan 3 vs 3 Genoa | Empoli 0 vs 0 Frosinone | Hellas Verona 2 vs 1 Fiorentina | Cagliari 1 vs 1 Lecce | Sassuolo 1 vs 0 Inter Milan | Monza 2 vs 2 SS Lazio | Torino 0 vs 0 Bologna European Championships Qualifying: Plymouth Argyle 1 vs 0 Hull City | Birmingham City 1 vs 0 Norwich City | Coventry City 1 vs 2 Queens Park Rangers | Stoke City 4 vs 0 Bristol City | Swansea City 0 vs 1 Millwall FC | Leeds United 1 vs 2 Southampton | Ipswich Town 2 vs 0 Huddersfield Town | Sunderland 0 vs 2 Sheffield Wednesday | Rotherham United 5 vs 2 Cardiff City | Middlesbrough 3 vs 1 Watford | Leicester City 0 vs 2 Blackburn Rovers | West Bromwich Albion 3 vs 0 Preston North End English Championship: Plymouth Argyle 1 vs 0 Hull City | Birmingham City 1 vs 0 Norwich City | Coventry City 1 vs 2 Queens Park Rangers | Stoke City 4 vs 0 Bristol City | Swansea City 0 vs 1 Millwall FC | Leeds United 1 vs 2 Southampton | Ipswich Town 2 vs 0 Huddersfield Town | Sunderland 0 vs 2 Sheffield Wednesday | Rotherham United 5 vs 2 Cardiff City | Middlesbrough 3 vs 1 Watford | Leicester City 0 vs 2 Blackburn Rovers | West Bromwich Albion 3 vs 0 Preston North End Weather: Katima Mulilo: 18° | 35° Rundu: 16° | 34° Eenhana: 14° | 34° Oshakati: 17° | 33° Ruacana: 16° | 33° Tsumeb: 17° | 32° Otjiwarongo: 14° | 30° Omaruru: 15° | 32° Windhoek: 13° | 28° Gobabis: 16° | 29° Henties Bay: 13° | 19° Wind speed: 19km/h, Wind direction: S, Low tide: 08:09, High tide: 14:30, Low Tide: 20:18, High tide: 02:00 Swakopmund: 15° | 17° Wind speed: 20km/h, Wind direction: SW, Low tide: 08:07, High tide: 14:28, Low Tide: 20:16, High tide: 02:00 Walvis Bay: 14° | 21° Wind speed: 25km/h, Wind direction: SW, Low tide: 08:07, High tide: 14:27, Low Tide: 20:16, High tide: 02:00 Rehoboth: 15° | 29° Mariental: 16° | 31° Keetmanshoop: 17° | 31° Aranos: 18° | 31° Lüderitz: 13° | 22° Ariamsvlei: 17° | 34° Oranjemund: 12° | 20° Luanda: 25° | 29° Gaborone: 15° | 30° Lubumbashi: 16° | 27° Mbabane: 14° | 28° Maseru: 10° | 25° Antananarivo: 10° | 22° Lilongwe: 17° | 29° Maputo: 18° | 30° Windhoek: 13° | 28° Cape Town: 15° | 16° Durban: 18° | 29° Johannesburg: 16° | 25° Dar es Salaam: 22° | 30° Lusaka: 19° | 30° Harare: 14° | 29° Economic Indicators: Currency: GBP to NAD 23.09 | EUR to NAD 19.82 | CNY to NAD 2.55 | USD to NAD 18.39 | DZD to NAD 0.14 | AOA to NAD 0.02 | BWP to NAD 1.31 | EGP to NAD 0.38 | KES to NAD 0.14 | NGN to NAD 0.01 | ZMW to NAD 0.67 | ZWL to NAD 0.04 | BRL to NAD 3.64 | RUB to NAD 0.2 | INR to NAD 0.22 | USD to DZD 134.19 | USD to AOA 834.06 | USD to BWP 13.62 | USD to EGP 47.9 | USD to KES 133.48 | USD to NGN 1380 | USD to ZAR 18.4 | USD to ZMW 27.1 | USD to ZWL 321 | Stock Exchange: JSE All Share Index 76428.31 Up +0.50% | Namibian Stock Exchange (NSX) Overall Index 1700.24 Up +0.45% | Casablanca Stock Exchange (CSE) MASI 13403.47 Up +0.61% | Egyptian Exchange (EGX) 30 Index 26113.71 Up +3.34% | Botswana Stock Exchange (BSE) DCI Same 0 | NSX: MTC 7.75 SAME | Anirep 8.99 SAME | Capricorn Investment group 17.34 SAME | FirstRand Namibia Ltd 49 DOWN 0.50% | Letshego Holdings (Namibia) Ltd 4.1 UP 2.50% | Namibia Asset Management Ltd 0.7 SAME | Namibia Breweries Ltd 31.49 UP 0.03% | Nictus Holdings - Nam 2.22 SAME | Oryx Properties Ltd 12.1 UP 1.70% | Paratus Namibia Holdings 11.99 SAME | SBN Holdings 8.45 SAME | Trustco Group Holdings Ltd 0.48 SAME | B2Gold Corporation 47.34 DOWN 1.50% | Local Index closed 677.62 UP 0.12% | Overall Index closed 1534.6 DOWN 0.05% | Osino Resources Corp 19.47 DOWN 2.41% | Commodities: Gold US$ 2 323.63/OZ UP +0.95% | Copper US$ 4.58/lb UP +1.12% | Zinc US$ 2 924.30/T DOWN -0.08% | Brent Crude Oil US$ 84.20/BBP UP +0.85% | Platinum US$ 959.56/OZ UP +0.39%