
Eswatini Government: Digital Outages Cripple Systems After Alleged Hack
The Eswatini government confirmed widespread disruptions to critical digital services, including elderly grant payments, road transport permits, scholarship applications, and the e-Visa system, on September 23, 2026, following allegations of a hack at the Royal Science and Technology Park (RSTP).
This incident carries significant legal implications, primarily highlighting the growing cybersecurity risks faced by public institutions and the potential for severe disruption to essential government services. For legal practitioners, it underscores the critical importance of robust cybersecurity frameworks, data protection compliance, and incident response planning within both public and private sectors. The compromise of government systems could lead to breaches of sensitive personal data, raising questions about state liability, citizen privacy rights, and the potential for civil claims if individuals suffer harm due to data exposure or service unavailability. Businesses reliant on these government digital platforms, such as those involved in transport, education, or international trade requiring permits and visas, would have faced operational challenges and potential financial losses, prompting a review of contractual obligations and force majeure clauses.
The legal context for such an event in Eswatini primarily involves the Electronic Communications and Transactions Act of 2009 (ECT Act), which provides a foundational framework for electronic transactions and data integrity, though it may not fully address the complexities of modern cybercrime and data breaches. Discussions around a more comprehensive data protection law and a dedicated Computer Crime and Cybercrime Bill indicate an evolving legislative landscape, which this incident may accelerate. Criminal investigations could be initiated under existing statutes related to property damage or theft, even in the absence of specific cybercrime legislation. The Ministry of Information, Communications and Technology (ICT) would be the primary regulatory and oversight body, responsible for addressing the breach and implementing corrective measures.
The key parties involved include the Government of Eswatini, particularly the Ministry of Information, Communications and Technology, and the Royal Science and Technology Park (RSTP), which was allegedly breached. The unnamed hackers represent the adversarial party, while the citizens of Eswatini who rely on the affected services are the primary victims of the disruption. The outcome of any criminal investigation or civil action related to this incident is not reported in the excerpt.
Practitioners in Eswatini should advise clients, especially those operating in regulated industries or handling sensitive data, to conduct thorough cybersecurity audits, develop comprehensive incident response plans, and ensure compliance with existing and anticipated data protection legislation. Monitoring the legislative developments in cybersecurity and data protection will be crucial, as this high-profile incident is likely to spur legislative action. Furthermore, businesses should review their contracts with government entities or third-party service providers to understand their rights and obligations in the event of service disruptions caused by cyber incidents.
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in Eswatini
Wansom is AI and can make mistakes.
