Cybercrime

In a landmark decision that underscores the increasing severity and sophistication of cybercrimes in South Africa, Lucky Majangandile Erasmus has been convicted of multiple charges under the Cybercrimes Act of 2021. This conviction has sent ripples through the nation’s cybersecurity landscape, marking a significant milestone in the fight against cybercriminal activities.

Detailed Background 

Lucky Majangandile Erasmus, a 36-year-old ex-employee of Ecentric Payment Systems, a leading South African payment service provider, participated in a complex cyberattack against the company in 2023. Erasmus and his co-accused, Felix Unathi Pupu, aged 43 and also a former employee of Ecentric, abused their insider knowledge to undermine Ecentric’s IT infrastructure. The two illegally installed unauthorized remote access software, which enabled them to breach the company’s infrastructure and steal sensitive data. This breach facilitated an attempted ransomware scheme, where an unknown party contacted Ecentric’s CEO, demanding substantial payments to prevent the public release of the compromised data.

The initial ransom demand, released on November 14, 2023, amounted to $534,260 (about R9.47 million), to be paid within 16 hours, accompanied by threats to disseminate the data across several platforms, including Ecentric’s competitors, stakeholders, and regulators, within 30 hours if the demand was not fulfilled. On November 30, 2023, a subsequent demand increased the ransom to $1 million (about R17 million), along with additional threats to disclose the data breach.

Ecentric declined to remit the ransom; however, the assault incurred financial losses amounting to R794,808.51 for four of its retail clients, as stated by the South African Police Service (SAPS).

Erasmus was apprehended on December 14, 2023, following an investigation supported by digital forensics company Cyanre, which played a pivotal role in identifying and tracing the suspects. The case was prosecuted by the Directorate for Priority Crime Investigation (Hawks) and adjudicated in the Bellville Specialised Commercial Crimes Court in Cape Town.

Investigation and Examination

The case revolved around an attempted ransomware scheme orchestrated by Erasmus in collaboration with his co-accused, Felix Unathi Pupu. The duo was implicated in a malicious plot that involved demanding ransom payments from the victims and using threats to expose sensitive data in the event of non-compliance. Their targets included several organisations that relied heavily on technology for their operations, making them vulnerable to such malicious acts.

The meticulous investigation conducted by the Directorate for Priority Crime Investigation, commonly known as the Hawks, brought to light the intricate details of the attack initiated by the accused. 

Experts noted that the ransomware used in the attack displayed advanced encryption techniques, which made data recovery without payment nearly impossible. This level of technological prowess raised alarms within the cybersecurity community, as it signalled a shift towards more sophisticated tactics being employed by cybercriminals in the region.

Authorities faced significant challenges in tracing the origins of the attack, given the layers of anonymity employed by Erasmus and Pupu. However, a breakthrough came when digital forensic analysts identified traces of the ransomware’s source code linked to previous cyberattacks in the global sphere. This connection not only provided crucial evidence but also underscored the expanding network of transnational cybercrime.

In addition to these technical aspects, the case also brought attention to the human cost of such crimes. Employees of targeted organisations faced uncertainty and stress as they grappled with the potential exposure of sensitive data. This added a moral dimension to the legal efforts, reinforcing the urgency of a robust response to cybercrime.

After a thorough examination of digital evidence, the Hawks, in consultation with the forensic specialists at Cyanre, were able to establish a solid case against Erasmus and Pupu.

Investigation and Digital Forensics

The investigation was a collaborative effort involving Ecentric, the Hawks, and Cyanre, a digital forensics firm. Cyanre’s expertise was instrumental in managing the security breach and tracing the suspects. The firm emphasized the importance of robust digital forensic evidence in securing the conviction, highlighting that preserving logs, access records, and system data immediately after a breach is critical for admissible evidence in legal proceedings. 

The Role of Ecentric Payment Systems

Central to this case was Ecentric Payment Systems, a payment processing alternative that fell victim to the attempted cyberattack. The scheme aimed at targeting the company’s critical infrastructure to extort financial gain through ransom demands. This attack, which could have severely disrupted services and compromised sensitive customer information, highlighted the vulnerabilities present within South African corporations’ cybersecurity frameworks.

The involvement of Ecentric Payment Systems was pivotal in ensuring rapid action against the cybercriminals. As one of the targeted organisations, they displayed exemplary vigilance by identifying the ransomware attack early and engaging with forensic experts and law enforcement. Ecentric’s proactive approach not only mitigated potential damage but also set a precedent for how organisations should respond to cybersecurity threats of this magnitude.

Ecentric’s management promptly contacted law enforcement upon receiving the ransom demand. This cooperation expedited the investigation, ensuring that the perpetrators could be apprehended before significant damage occurred.

Proceedings in the Bellville Specialised Commercial Crimes Court

The legal proceedings took place in the Bellville Specialised Commercial Crimes Court, where Erasmus’s charges were laid out in detail. The allegations included conspiracy to commit extortion, offences relating to computer data and systems, and breaches specifically outlined under the Cybercrimes Act of 2021.

The court proceedings delved into the intricate web of operations orchestrated by Erasmus and Pupu. Detailed testimonies from forensic experts shed light on how the cyberattack was planned and executed, exposing the vulnerabilities in digital infrastructures that were exploited. The prosecution presented compelling evidence, including decrypted communications and financial records, which revealed the extent of the financial motives behind the crime.

Legal experts highlighted the pivotal role of the Cybercrimes Act in framing the charges, marking one of the first significant cases to leverage this relatively new legislation. The trial also underscored the importance of public-private partnerships in tackling such sophisticated threats. Several witnesses from Ecentric Payment Systems testified, offering crucial insights into how the organisation navigated the crisis, ensuring the attackers were thwarted before they could achieve their objectives.

Erasmus entered into a plea agreement, a strategic move that facilitated the judicial process while ensuring that he accepted accountability for his actions. This agreement not only revealed the operational strategies employed by the conspirators but also facilitated further investigations into other potential accomplices in the fraud.

The case also highlighted the critical need for organisations to enhance their cybersecurity readiness. By identifying gaps in their digital defences, businesses can not only protect themselves from future attacks but also contribute to a national culture of resilience against cybercrime. This incident served as a wake-up call, urging companies to adopt advanced cybersecurity tools, conduct regular audits, and foster a workforce trained to recognise and respond to threats effectively.

Furthermore, the collaboration between Ecentric Payment Systems, law enforcement, and forensic experts illustrated the power of shared expertise and information. Their coordinated efforts not only brought the perpetrators to justice but also set a benchmark for inter-agency and public-private partnerships in combating cybercrime. Lessons from this case stress the urgency of fostering such alliances to ensure a more unified and efficient response to digital threats.

Charges and Plea Agreement

Erasmus faced 20 charges under the Cybercrimes Act, including:

  1. Cyber fraud: Manipulating or interfering with Ecentric’s systems to obtain unauthorized benefits.
  2. Theft of data: Unlawfully accessing and extracting sensitive company data.
  3. Attempted cyber extortion: Attempting to extort Ecentric through ransomware demands.
  4. Violations of specific sections of the Cybercrimes Act, such as section 12, which addresses unauthorised access to systems or data.

Erasmus entered into a plea agreement with the State, which led to his conviction on 17 of the 20 charges. The plea deal likely expedited the legal process and may have influenced the sentencing outcome, as it demonstrated cooperation with the authorities. His co-accused, Felix Unathi Pupu, remained in custody, with his plea and sentencing scheduled for June 30, 2025.

Sentencing

On June 3, 2025, the Specialised Commercial Crimes Court sentenced Erasmus to eight years’ imprisonment, resulting in an effective sentence of five years’ direct imprisonment. Additional conditions included:

  1. Erasmus was declared unfit to possess a firearm. 
  • He was ordered not to commit any further offenses during the fiveyear suspension period, including fraud, conspiracy to commit fraud, theft, or violations of the Cybercrimes Act or the Trespass Act. A violation of these conditions would activate the suspended three-year sentence.

The sentencing reflects the court’s recognition of the severity of cybercrimes while balancing Erasmus’s cooperation through the plea agreement.

The Significance of Erasmus’s Conviction

The conviction of Lucky Majangandile Erasmus represents a crucial step in South Africa’s struggle against escalating cybercrime. The severity of the charges placed against him serves as a cautionary tale of the consequences faced by individuals who engage in cybercriminal activities. It is a timely reminder of the legal frameworks, such as the Cybercrimes Act, which were established to combat the rampant techdriven criminal behaviours that threaten economic stability and personal privacy.

Legal scholars and cybersecurity practitioners lauded the case as a watershed moment that showcased the effective application of the Cybercrimes Act, setting a precedent for future prosecutions under this law. This case also brought into sharp focus the role of ethical considerations in cybersecurity. Organisations were reminded that their ethical duty extends beyond protecting their assets to contributing to a collective digital defence. By fostering environments of transparency and cooperation, businesses can help build a fortified cyber ecosystem that aligns with societal needs for security and trust.

Moreover, the case illuminates the importance of collaboration among private enterprises, law enforcement, and digital forensic firms. The proactive measures taken by Ecentric Payment Systems in liaison with the Hawks and Cyanre demonstrated a model of best practices that other organisations can adopt to fortify their defences against similar threats.

In addition, the conviction has broader implications for South Africa’s cybersecurity landscape. It reflects not only the enforcement of stringent legal measures but also the commitment of the authorities to promote a safer digital environment for all citizens. The South African government has recently intensified its focus on cybersecurity issues, ensuring that organisations that might be targets of cybercriminal activities are safeguarded against the financial and reputational damage that such incidents may inflict.

Implications for South Africa’s Future Cybersecurity

As cyber threats continue to evolve, so too must the legislative measures and responses to combat them. Erasmus’s conviction underscores the importance of constant adaptation in the pursuit of robust cybersecurity strategies. It serves as a crucial reminder to both individuals and organisations of their vulnerabilities in an increasingly digital world, encouraging them to invest in the necessary resources and practices to shield themselves from future threats.

The case of Erasmus has also spurred conversations around the scalability of cybersecurity solutions in both urban and rural contexts within South Africa. While metropolitan businesses often have access to cutting-edge technologies and expertise, smaller enterprises and institutions in rural areas are left vulnerable due to limited resources and awareness. This disparity underscores the need for a national strategy that ensures the equitable distribution of cybersecurity resources.

In this vein, public-private partnerships must be extended to support under-resourced sectors, providing training programs, affordable access to protective technologies, and awareness campaigns. The South African government, in collaboration with tech innovators, has a pivotal role to play in bridging this digital divide, fostering an environment where cybersecurity is not a privilege but a fundamental requisite for all.

Additionally, the Erasmus case has sparked renewed interest in the role of education in promoting long-term resilience against cyber threats. Universities and technical training institutions are being called upon to include comprehensive cybersecurity curricula that equip students with the skills necessary to anticipate and counter advanced digital risks. These efforts, coupled with community outreach programs, can transform the fight against cybercrime into a collective societal effort.

Conclusion

The successful prosecution of Lucky Majangandile Erasmus stands as a testament to South Africa’s fight against cybercrime, demonstrating the effectiveness of the Cybercrimes Act and the importance of digital forensics in securing convictions. It is an invaluable step toward establishing a more secure digital framework in South Africa, promoting a culture where cybercriminal activities are met with serious consequences. Stakeholders across the board—from governmental institutions to private enterprises—must heed the lessons learned from this case to bolster the country’s cybersecurity measures and safeguard against the impending threats in a cyber-dependent future. With Erasmus sentenced to an effective five years in prison and his co-accused awaiting trial, the case serves as a warning to potential cybercriminals and reinforces South Africa’s commitment to protecting its digital infrastructure.

By: Natascha Miller, LLB, BA [Forensics]


LEAVE A REPLY

Please enter your comment!
Please enter your name here

four × one =