Advertisement

SPECIAL INVESTIGATIVE REPORT

COLLAPSE OF INTERNAL CONTROLS
Ex-Information Security Manager Exposes “Syndicate” Operation and Mass Vulnerabilities at University of the Western Cape

CAPE TOWN — A landmark ruling in the Western Cape Labour Court has paved the way for a high-stakes legal showdown between the University of the Western Cape (UWC) and its former Information Security Manager. The court dismissed a special plea filed by UWC seeking to block the matter, granting jurisdiction to hear a case under the Protected Disclosures Act following allegations of systematic corruption, compromised whistleblowing channels, vendor fraud, and severe cybersecurity failures at the institution.

Advertisement

The explosive disclosures reveal a pattern of executive overreach, retaliatory disciplinary measures, compromised internal audit mechanisms, and millions of Rands lost to unchecked cyber breaches and inflated vendor billing.


1. Executive Summary & Whistleblower Backstory

The whistleblower served as UWC’s first Information Security Manager in roughly ten years, taking office at a time when the university’s digital perimeter was severely unmonitored.

According to court filings and public disclosures:

  • Contract Termination & Legal Victory: After a series of internal suspensions, the whistleblower’s employment contract was terminated on March 3, 2025. Following an initial challenge at the Commission for Conciliation, Mediation and Arbitration (CCMA) resulting in a finding of an automatically unfair dismissal, the matter moved to the Labour Court.

  • Special Plea Dismissed: UWC filed a special plea asserting the Labour Court lacked jurisdiction to hear the case. The Labour Court in Cape Town ruled against UWC, allowing the Protected Disclosures Act suit to proceed.

  • Financial Burden: The whistleblower reports having personally spent over R180,000 in legal fees across three years to defend against the university’s actions, including enduring six months of enforced suspension.


2. Key Fraud & Cybersecurity Allegations

The R20 Million Telecom Billing Hack

Shortly before or around the onset of the whistleblower’s tenure, UWC suffered an uncontained cyber breach.

  • Exploit: A hacker compromised the university’s Virtual Private Network (VPN) using student credentials intended for remote learning data allocations.

  • Financial Impact: The attacker systematically drained data resources, accumulating a bill exceeding R20 million across major telecommunications providers (Telkom, Vodacom, and MTN).

  • Concealment: The massive R20 million loss was reportedly never disclosed publicly or to key regulatory authorities.

Vendor Overbilling & Fraud Allegations

While auditing network security infrastructure, the whistleblower evaluated UWC’s internal threat monitoring platform, Darktrace.

  • Procurement Irregularity: During negotiations to acquire necessary supplementary services worth approximately R3 million, IT vendor First Technology Western Cape submitted an invoice containing an unauthorized markup of over R1 million above the agreed proposal.

  • Intervention & Reversal: The whistleblower flagged the inflated invoice, forcing the supplier to retract the extra charge.

  • Anti-Corruption Breach: Despite UWC’s internal Anti-Corruption and Fraud Policy mandating formal reporting and debarment of vendors engaging in fraudulent billing, ICT leadership reportedly bypassed reporting protocols.

  • Subsequent Approval: It is alleged that while the whistleblower was placed on forced suspension, UWC executives approved the contract and disbursed the R1 million sum previously flagged as fraudulent.


3. Detailed Timeline of Retaliatory Actions

Date Event
Early 2025 Inflated invoice stopped by whistleblower (First Technology)
Formal fraud report submitted to ICT Management
Two Weeks Later Immediate suspension issued for “insubordination”
Nov 5, 2025 Whistleblower recalled from USA for formal disciplinary hearing
Dec 15, 2025 Cleared of all charges and returned to work
Same Day Immediately served with second charge sheet (defamation claim)
March 3, 2025/2026 Period Contract terminated → Referral to CCMA & Labour Court
  • First Suspension (March 2025): Two weeks after reporting the vendor billing irregularity to ICT leadership—specifically Raymond Crown (then Director of ICT) and Gayle Frank (Senior Manager: Governance, Risk, and Compliance)—the whistleblower was locked out of network access and suspended for alleged insubordination.

  • VC Disclosure: The whistleblower submitted a comprehensive formal disclosure to outgoing Vice-Chancellor Professor Pretorius, outlining that the suspension was direct retaliation for stopping the R1 million vendor inflation.

  • Recall from Overseas & Exoneration: On November 5, while attending to personal matters in the United States, the whistleblower was abruptly ordered to return to South Africa for a formal hearing. The internal hearing completely cleared the whistleblower of all charges, leading to a reinstatement date of December 15.

  • Immediate Second Charge: On the very day of returning to the office (December 15), the whistleblower received notification of a second disciplinary proceeding. ICT Director Raymond Crown alleged he was defamed by the explanatory statements the whistleblower submitted during the initial suspension defense.

  • Termination: Following hearings running from February through late March, the employment relationship was severed.


4. Breakdown of Institutional Failures & “The Syndicate”

The whistleblower asserts that operational controls at UWC have disintegrated, enabling a senior executive group to act as an unmonitored “syndicate” that manipulates internal oversight structures.

Operational Area Specific Breakdown / Allegation
Whistleblower Hotline The institutional ethics hotline (managed via KPMG) is reportedly breached. Whistleblower submissions alleging executive misconduct were allegedly leaked directly back to the individuals being reported, enabling target victimisation.
Institutional Governance Emails addressed to the Chairperson of Council were reportedly deleted from mailboxes prior to receipt. The current Vice-Chancellor, Professor Robert Balfour, was informed but stated inability to intervene, referring the matter externally.
Legal Threat against Security Ops After raising hotline breaches with internal risk personnel (e.g., Shehaan Reddi), external law firm Weber Wentzel was retained to issue a “cease and desist” demand against the university’s own Information Security Manager.
Internal & External Audit Scope External audit firms (including Ernst & Young and KPMG) are required to continuously tender for limited audit scopes, restricting their ability to independently investigate operational fraud.
Data Integrity & Deletion During periods of employee suspension, the whistleblower’s official email archives were unauthorisedly wiped. Furthermore, contract staff hired under security remediation projects were systematically dismissed.

5. Ongoing IT Vulnerabilities & Compliance Risks

Beyond administrative governance failures, the disclosures paint a critical picture of UWC’s day-to-day technological stability and statutory non-compliance:

  • Payroll Manipulation & Ghost Workers: Implementation of the Adapt IT payroll module was reportedly rushed without securing file ownership mandates. This vulnerability resulted in missing funds allocated for student Work-Study programs and the insertion of “ghost workers” into payroll runs.

  • Library System Crash & Unreported Loss: A major infrastructure failure caused the UWC Library database to crash, erasing student research data. Rather than issuing formal incident notifications, staff allegedly rebuilt the system manually to hide the total loss of data.

  • Network Hijacking & Unauthorised Third-Party Access: During an unannounced outage caused by an external intrusion where main switches and firewalls were remotely toggled off, internal staff hid the incident and recruited an unauthorised former employee (currently employed in the private retail sector) to manually restore the network without oversight.

  • POPIA & Cloud Policy Violations: Institutional and student data was migrated to offsite third-party hosts in direct violation of the Protection of Personal Information Act (POPIA) and Department of Public Works cloud infrastructure directives, exposing UWC to catastrophic data loss without recovery guarantees.

  • Contract Discrepancies: Unapproved expenditure continues around policy drafting, where consulting fees up to R500,000 are routinely paid annually for recurring drafts that are never submitted for formal Council approval.

  • Over 100 Outstanding Vulnerabilities: At the time of the Security Manager’s departure, over 100 severe security vulnerabilities remained unaddressed due to critical skill deficiencies within the ICT department.


6. Current Status & Next Steps

With the Labour Court ruling that UWC must face the Protected Disclosures Act suit, full evidentiary trials will proceed in the Western Cape Labour Court. The court has further required UWC to present evidence proving whether the University Council explicitly authorised the legal expenditure incurred to fight the whistleblower.

The whistleblower maintains that all claims submitted to court are backed by contemporary written correspondence, audit logs, and internal filings submitted directly to successive Vice-Chancellors and oversight bodies.

— END OF REPORT —

Advertisement