More than a year after Ekurhuleni launched disciplinary proceedings against its former chief information officer, questions remain over how much money the metro ultimately lost in a massive cybercrime incident — and whether everyone involved has been held accountable.
- Former Ekurhuleni CIO dismissed after lengthy suspension
- How Ekurhuleni’s R2 billion cybercrime crisis unfolded
- Security weaknesses allegedly left municipal systems exposed
- Fraud was reportedly discovered through financial analysis
- Alleged overnight cybersecurity loophole raises concern
- Consultants and officials also came under scrutiny
- Three senior officials dismissed
- Where did the missing money go?
- Ratepayers are also paying for the investigation
- Council oversight faces a critical test
- Ekurhuleni’s cybersecurity crisis is bigger than one official
- The unanswered questions could prove more important than the disciplinary outcome
The Freedom Front Plus says the City of Ekurhuleni’s latest progress report has provided little clarity on some of the most important issues surrounding the affair.
Among its concerns is the cost of the disciplinary process, which the party says has already exceeded R1.56 million for ratepayers, with further legal expenses potentially still to come.
The controversy centres on a combination of alleged weaknesses in the metro’s information technology systems, manipulated municipal accounts, fraudulent invoices and an estimated R2 billion in losses associated with cybercrime.
According to information presented to Parliament, approximately R1.19 billion had yet to be recovered as of May 2026.
Former Ekurhuleni CIO dismissed after lengthy suspension
Moloko Monyepao, Ekurhuleni’s former CIO, was placed on precautionary suspension on 27 March 2025 following allegations of serious mismanagement linked to financial losses suffered by the municipality.
He remained suspended for more than a year before being dismissed.
Ekurhuleni said the disciplinary action arose from concerns involving its billing systems, meter readings, account manipulation and the management of business systems.
The case emerged as the metro grappled with a much larger financial and cybersecurity crisis.
The Freedom Front Plus’s Denise Janse van Rensburg, an Ekurhuleni councillor who serves on the Finance Committee and Ethics and Integrity Committee, said the latest council report had not answered several fundamental questions.
Her concern is not limited to the disciplinary process itself. The party wants a complete picture of the financial damage, the money recovered and the measures implemented to prevent similar incidents from happening again.
How Ekurhuleni’s R2 billion cybercrime crisis unfolded
The scale of the problem became clearer during a briefing to Parliament’s Standing Committee on Public Accounts, or SCOPA, in May 2026.
Ekurhuleni told the committee that it had experienced what it described as a “digital state of emergency”, with approximately R1.19 billion still outstanding from the estimated R2 billion stolen through a prolonged cybercrime operation.
The municipality said the criminal activity was uncovered during the 2024/25 financial year after officials began analysing quarterly financial reports.
The investigation reportedly uncovered suspicious changes to municipal accounts and invoices.
According to testimony presented to SCOPA, individuals gained access to internal municipal systems and allegedly manipulated accounts, removed debts and generated invoices through which payments could be made.
The exact mechanics and responsibility for individual transactions remain matters for investigation and due process.
Security weaknesses allegedly left municipal systems exposed
Ekurhuleni’s own testimony suggested that the metro’s cybersecurity controls had significant vulnerabilities.
Former acting city manager Tsholofelo Koopedi told SCOPA that the problem might not necessarily have been one continuous attack lasting a year. Instead, he suggested it could have involved multiple breaches occurring over an extended period.
One of the examples he gave highlighted the potential risks associated with the municipality’s wireless and remote-access infrastructure.
Koopedi said a person could allegedly park near a municipal licensing facility in Bedfordview, connect to publicly accessible Wi-Fi and potentially gain access to the city’s VPN.
The claim illustrates the seriousness of the alleged security weaknesses, although the precise circumstances and extent of any unauthorised access would need to be established through forensic and criminal investigations.
Koopedi also told the committee that the municipality believed its security infrastructure had been deliberately compromised to facilitate fraudulent activity.
Fraud was reportedly discovered through financial analysis
The cybercrime was not initially identified through an automated security alert.
Instead, officials reportedly began noticing discrepancies while comparing the municipality’s income against its budget.
Jongizizwe Dlabathi, Ekurhuleni’s MMC for Finance, told SCOPA that whistleblowers had raised concerns about large-scale fraud within the municipality.
Those concerns prompted further investigation.
The city’s ICT department subsequently came under scrutiny, with Ekurhuleni reportedly seizing about 35 computers for forensic examination.
The matter was also referred to the South African Police Service and the Special Investigating Unit.
That escalation indicates that the metro viewed the allegations as potentially extending well beyond an internal administrative failure.
Alleged overnight cybersecurity loophole raises concern
One of the more troubling findings described by the municipality involved its cybersecurity monitoring arrangements.
Ekurhuleni said officials discovered that an ICT-related loophole meant cybersecurity monitoring was not operating during certain overnight hours.
The gap reportedly ran from 18:00 to 06:00.
The municipality suspected that account manipulation and the creation of fraudulent invoices could have taken place during this period.
If established, such a gap would raise serious questions about basic cyber-risk management, particularly for a municipality operating financial and billing systems containing sensitive information and large amounts of public money.
It also raises a broader governance issue: cybersecurity is not simply an IT concern.
For municipalities, weaknesses in digital controls can quickly translate into financial losses, compromised public records and potentially damaged confidence in local government.
Consultants and officials also came under scrutiny
Ekurhuleni said it had identified people who had previously been employed as consultants and were allegedly working with external parties to undermine the municipality’s systems.
The municipality has not publicly established criminal liability against every person implicated in these allegations, and individual responsibility remains subject to appropriate investigations and due process.
Nevertheless, the claims raise questions about how external contractors were appointed, monitored and given access to municipal systems.
The incident demonstrates why contractor access can be a significant cybersecurity risk.
Municipalities frequently rely on external service providers for specialised technical functions. But where third parties receive access to critical infrastructure, effective controls, monitoring and accountability become essential.
Three senior officials dismissed
At the end of July, Ekurhuleni announced the dismissal of three senior officials.
Monyepao was among them.
The other two officials were HR director Linda Gcasheka and head of legal services Kemi Behari. Their dismissals followed their implication at the Madlanga Commission.
The disciplinary action represents a significant consequence for senior management.
However, the Freedom Front Plus argues that dismissal alone does not resolve the wider financial and governance questions surrounding the cybercrime affair.
The party wants the council to establish the full extent of the losses and determine what happened to the money.
Where did the missing money go?
This is arguably the biggest unanswered question.
Ekurhuleni told Parliament that around R1.19 billion had not been recovered by May 2026.
The figure is particularly significant because the estimated total loss was approximately R2 billion.
The recovery process therefore represents a major public-interest issue.
Ratepayers ultimately have a stake in knowing how much money can realistically be recovered, what assets or funds have been traced and whether those responsible can be held financially accountable where legally possible.
The Freedom Front Plus says the latest progress report did not provide sufficient clarity on the amount recovered.
It also questioned whether the municipality had completed investigations into all officials, service providers and other parties who may have played a role.
Ratepayers are also paying for the investigation
The political controversy extends beyond the original financial losses.
According to the Freedom Front Plus, the disciplinary process involving Monyepao has already cost ratepayers more than R1.56 million, excluding additional legal expenses that may still arise.
That creates a difficult accountability equation.
The municipality has to spend money investigating allegations and conducting disciplinary proceedings properly. At the same time, every rand spent on the process adds to the financial burden associated with a crisis that has already allegedly cost the city billions.
This makes effective oversight particularly important.
The objective cannot simply be to complete disciplinary hearings. It must also be to establish what went wrong, recover public money where possible, close security gaps and ensure that similar failures do not recur.
Council oversight faces a critical test
Van Rensburg argues that the Ekurhuleni Council cannot effectively exercise its oversight responsibilities by simply receiving and noting progress reports.
The Freedom Front Plus says councillors need detailed information about the financial impact, recovery of losses and consequence management.
That argument goes to the heart of municipal accountability.
A progress report can demonstrate that an investigation is moving forward, but it does not necessarily answer the questions residents ultimately want answered:
How much was lost? How much has been recovered? Who was responsible? Were all relevant parties investigated? What has been fixed? And how much has the entire process cost?
Until those questions are answered comprehensively, the political and financial fallout from Ekurhuleni’s cybersecurity crisis is unlikely to disappear.
Ekurhuleni’s cybersecurity crisis is bigger than one official
The dismissal of a senior municipal technology executive may provide a clear disciplinary outcome, but the broader affair points to systemic questions.
If unauthorised users could access critical systems, municipal accounts could be manipulated and fraudulent invoices could allegedly be created without immediate detection, then the problem cannot be viewed solely through the actions of one employee.
It raises questions about governance structures, access controls, monitoring, contractor management, internal auditing, financial controls and the municipality’s broader cybersecurity maturity.
That is why the recovery of money is only one part of the story.
Ekurhuleni also needs to demonstrate that the vulnerabilities exposed by the incident have been properly addressed.
Otherwise, recovering yesterday’s losses will do little to protect tomorrow’s revenue.
The unanswered questions could prove more important than the disciplinary outcome
For residents and ratepayers, the ultimate measure of this saga will not simply be how many officials were suspended or dismissed.
It will be whether public money is recovered, whether those responsible are held accountable through lawful processes and whether the municipality’s systems are now significantly harder to exploit.
The R1.56 million disciplinary bill is substantial in its own right, but it pales beside the estimated R2 billion financial impact of the cybercrime.
That disparity underscores why the investigation must go beyond individual disciplinary outcomes.
Ekurhuleni now faces the difficult task of demonstrating that it understands the full extent of the breach, can account for the missing funds and has permanently strengthened the systems designed to protect public money.
Until it does, the question raised by the Freedom Front Plus remains difficult to dismiss: how much of the R2 billion can be accounted for, and who will ultimately be held responsible for the losses?


