An opinion piece built on public reporting. Where claims are allegations from sources, we say so.
On Friday, 18 September 2026, the Royal Science and Technology Park (RSTP) confirmed it was dealing with an “incident” at the National Data Centre, the facility that hosts much of the government’s digital machinery. Within days, at least 12 government digital services and platforms had been disrupted, according to Times of Eswatini. The list is not abstract: the Government in Your Hand app, e-Visa, company registration, the government website, the Integrated Financial Management Information System (IFMIS), and the Elderly Grant Application and Payment system.
RSTP has confirmed the incident and says engineers and outside experts are working around the clock to restore services. Its communications officer, Senzo Malaza, said the organisation is “dealing with” the incident and has brought in external expertise. RSTP has not confirmed the allegations circulating on social media that the centre was hacked or that a ransom has been demanded.
Separately, Swazi Bridge has reported, citing multiple sources, that hackers breached the centre and are demanding one million euros (roughly E18 to E19 million), that South African cyber security experts were flown in to help contain the breach, and that the National Civil Registry’s identity and passport records were spared because they sit on a separate mainframe isolated from the network the attackers reached. Those specific claims remain allegations from unnamed sources until government confirms them. The disruption itself is confirmed.
What this means for ordinary Emaswati
A pension payment, a licence renewal, a company registration, a government payment: these are the small, unglamorous transactions that decide whether a household eats and whether a business trades. When the systems that run them stall, the harm is not felt in a boardroom. It is felt at the counter, at the border, and in the queue.
That is the uncomfortable truth about a small state with a single national data centre. There is no redundancy to lean on. One breach, one ransomware event, one failed licence renewal, and a whole administration can be forced back onto pen and paper for weeks. Eswatini is not unusual in this, but it is unusually exposed, because everything runs through one place.
What it means for businesses
There is a version of this story that businesses read as “government problem.” That reading is wrong.
If a national data centre, with a threat-management system and a security budget, can be taken down, then no small business can assume it is too small to be a target. The attackers are not choosing victims by size. They are choosing them by weakness: an unpatched server, an expired licence, a stolen password, a WordPress site nobody has updated since it was built.
The operational lesson is simple and it is the same lesson the RSTP case keeps teaching: security is maintenance, not a one-time purchase. Software licences expire. Patches stop arriving. Firewalls reach end of life. The people who knew how the systems worked leave. Any one of those is survivable. All of them at once, for years, is how a centre ends up defenceless against an attack that was never especially sophisticated.
How it got here (what the reporting alleges)
This is the part that should worry every taxpayer. Swazi Bridge’s investigation, based on interviews and internal documents, describes a pattern of underfunding and neglect stretching back years. We report it here as the publication’s findings and its sources’ allegations, not as proven fact:
- Funds earmarked for security licences were allegedly withheld and returned to the Consolidated Fund instead of being spent on the protections they were meant for, a matter the sources say the Auditor General flagged but Parliament did not pursue.
- Unpaid IBM software licences were allegedly followed by a government systems blackout lasting close to two weeks, with no public accounting.
- Engineers reportedly warned that firewalls and Cisco networking licences needed renewal and that uninterruptible power supply batteries had reached end of life. Sources say the warnings were not acted on, and that a replacement firewall procured for about E2.5 million had the wrong specifications and has sat unused for close to two years.
- Trained security engineers were reportedly dismissed, with the institution now relying on personnel from the former Government Computer Service, and annual ISO security audits said to have lapsed.
RSTP’s board chair, Advocate Jacky Fick, told Swazi Bridge she would prefer a coordinated response with the Minister. The ICT Ministry’s Principal Secretary, Prince Mshishimba Dlamini, confirmed a data system leak but said investigations were ongoing and that government could not yet say whether it was a hack, a breach, or a system takeover. He declined to discuss the ransom demand.
The part nobody wants to fund: people
Here is where we stop reporting and start arguing.
You can buy firewalls. You cannot buy the judgment to configure and maintain them overnight. The RSTP case, however it is finally explained, exposes a skills problem as much as a spending problem. A country cannot defend critical infrastructure it does not have the people to run. And the pipeline that produces those people starts in the classroom.
Eswatini’s educational institutions have to move faster than they are moving. A curriculum that treats cyber security as an afterthought, or that graduates students who can recite theory but have never once defended a live system, is not keeping up with the threat. The emergence of Botho University is a genuine opportunity: a new institution can build its programmes around the skills the country actually needs, and produce technicians and security professionals who can walk into a data centre and be useful on day one.
But this cannot be one university’s job. The national university must treat cyber security as a core discipline, not a module. And it must do it the way the industry does it: with boot camps, hands-on labs, mini servers students are expected to attack and defend, and capture-the-flag exercises where young people learn by breaking things in a safe room instead of reading about it in a slide deck.
There is a saying in this field: it takes a hacker to stop a hacker. That is not a call for lawlessness. It is a call for a generation trained to think like an attacker so they can defend like a professional. Eswatini has no shortage of sharp young people. What it has is a shortage of places where that sharpness is pointed at real systems, with real mentors, and internationally recognised certification at the end of it. Fix that pipeline and you fix the country’s defences at the source, not one procurement at a time.
What should happen now
Restoring the services is the urgent task, and it should be done without paying anyone a ransom if it can be avoided at all. But the larger questions cannot be buried the moment the systems come back online. There should be an independent forensic investigation, by the Auditor General and Parliament, into both the breach and the funding decisions that preceded it. And there should be a public, honest reckoning with the skills gap that made a national data centre this easy to reach.
Eswatini cannot afford to learn this lesson twice.
Sources
- Times of Eswatini, “National Data Centre hit by ‘incident’,” Stanley Khumalo, 24 September 2026 — https://times.co.sz/44621/news/national-data-centre-hit-by-incident
- Swazi Bridge, “EXCLUSIVE: GOVERNMENT PARALYSED AS HACKERS BREACH RSTP DATA CENTRE, DEMAND E18 Million (EUR 1 MILLION),” Manqoba Nxumalo, Dudu Lushaba and Samkelo Ngwenya, 22 September 2026 — https://swazibridge.com/article/index.php?iywtrre=eFeu
- Swazi Bridge, “DATA CENTRE LEAK: ONE MUST GO, EITHER CEO, BOARD OR MINISTER,” Manqoba Nxumalo, 24 September 2026 — https://swazibridge.com/article/index.php?iwtrre=eFet
- Swazi Bridge, “WE HAVE BROUGHT EXPERTS TO INVESTIGATE DATA CENTRE HACKING — RSTP BOARD CHAIR,” 23 September 2026 — https://swazibridge.com/article/index.php?iywtrre=eFev
Leave a Reply