
RECENT political commentary and statements from high-profile figures have sought to dismiss allegations of electoral irregularities in the 2024 South African elections as baseless political noise.
The prevailing narrative insists that the Independent Electoral Commission’s (IEC) systems are robust and fully audited and that the results are beyond reproach, urging the public to trust the technology.
However, a deep dive into the forensic Information and Communication Technology (ICT) expert reports, authored by independent information systems expert Dr Vusi Mhlongo, reveals a significantly different reality.
The documents dismantle the mainstream narrative, exposing a system plagued by mathematical impossibilities, a lack of genuine auditing, and a defensive institutional culture that refuses to acknowledge glaring errors.
Political analysts and commentators have frequently asserted that allegations of rigging “should be supported by credible evidence” and have characterised the challenges as “repeated claims without evidence”. Yet, a founding expert report seen by the Sunday Independent details a massive, empirical forensic data analysis that directly contradicts this claim.
In June 2024, Dr Vusi Mhlongo was approached to assess the integrity of the Electoral Commission of South Africa’s (IEC’s) ICT system. His methodology involved writing custom specialised programmes to systematically download and analyse all 23 291 Voting District (VD) level reports from the IEC’s own public dashboard. The findings were not baseless political assertions; they were mathematical certainties.
Mhlongo discovered that the national and regional ballot reports for the exact same voting stations were identical, a logical impossibility. Furthermore, the system failed to filter data by ballot type, resulting in independent candidates (who only run on regional ballots) incorrectly appearing with votes on National ballot reports.
Most damningly, the analysis revealed that the “Total Valid Votes” listed at the bottom of the VD reports were inflated to almost double the actual votes cast. Mhlongo noted: “For the national ballot results, the excess of total valid votes plus spoilt votes over and above the total votes cast reported in these reports is 15 858 564 votes. For the regional ballot results, the excess… is 16 038 258 votes.”
Consequently, the total valid vote percentages exceeded 100% in virtually every district. As Mhlongo stated unequivocally: “The total valid votes percentage reported on both the national and regional ballot voting station results reports exceeded 100% for all voting stations where votes were recorded (23 288 voting stations). The national ballot total valid votes percentage was, on average, 199%, and as high as 1 195%… The regional ballot total valid votes percentage was, on average, 201% and as high as 1 533%.”
To claim that such tangible, mathematical proof constitutes “claims without evidence” is to ignore the forensic reality of 46 582 analysed reports.
A central pillar of the defence of the IEC’s system is that it is “trusted” and has been independently reviewed by major auditing firms. President Cyril Ramaphosa and other defenders of the process have pointed to these audits as proof of a free and fair election.
Mhlongo’s reports expose this narrative as fundamentally misleading. The IEC relied heavily on a report by Deloitte to prove the system’s integrity. However, Mhlongo’s analysis of the Deloitte report reveals it was strictly limited. It was explicitly excluded from performing a “cybersecurity assessment” and a “code level analysis”, and did not “assess the capacity and performance of the NPE results system”.
More critically, the review was not even conducted on the live system used on election day. Mhlongo highlighted that “Deloitte’s review was only carried out on a copy of the IEC’s ICT system and not on the production/live system itself”. The review on this “pilot” copy concluded on May 27, 2024, weeks before the election, leaving a blind spot regarding any changes made to the live production system in the interim.
Mhlongo was scathing in his assessment of this arrangement: “Deloitte’s review was an attempt by the IEC to obtain a rubber stamping on the integrity of their system, without a thorough evaluation of the system.” He compares a functional user-interface review to “placing a test driver into a car and asking them to test drive it”, noting that this “will have absolutely no bearing on any hidden issues within the engine or any concealed buttons and controls”.
Without a line-by-line audit of the live production source code, Mhlongo warned that: “Undetected hidden threats lurking in the code, whether intentional or accidental, simply cannot be ruled out,” including malicious backdoors or logic bombs.
The narrative that the IEC’s technology is infallible was severely damaged by the events of May 31, 2024. On this date, while votes were actively being counted, the IEC’s results dashboard crashed for about two hours, resetting all numbers to zero.
The IEC claimed this was an accidental result of trying to “optimise” the ETL (extract, transform, load) process to make updates faster. Mhlongo’s report analyses this decision and finds it to be a gross violation of basic software engineering principles.
He wrote: “It is simply inconceivable and against known software development best practice guidelines and rules to make an update to a system: (a) at the height of processing and tension; and (b) in the absence of a critical system failure.”
When the IEC attempted to explain the crash in their responding affidavit, they claimed a “line of testing code remained behind” in the live system. Mhlongo pointed out that in a properly functioning version control environment, “there is never a possibility of anything ‘remaining behind’ anywhere”.
This admission, he argued, pointed to a “serious flaw with the design and functioning of the IEC’s digital votes capturing and reporting system, most especially with the manner in which it is updated and maintained”.
Rather than addressing the forensic evidence, the IEC’s response, detailed in a responding affidavit dated November 5, 2024 by Commissioner Sy Mamabolo, focused heavily on attacking the messenger.
In his replying affidavit dated December 2, 2024, Mhlongo noted with deep disdain that Mamabolo “strategically, intentionally and disrespectfully decided to repeatedly dispossess me of my correct title” by referring to him as “Mr Mhlongo”. Mhlongo counted “125 instances” of this deliberate omission, describing it as a bad-faith strategy to “shoot the messenger” and devalue his PhD qualifications from the University of KwaZulu-Natal (KZN).
Furthermore, when confronted with the tens of thousands of mathematically impossible VD reports, the IEC dismissed the findings. Mamabolo characterised the grave errors as “a storm in a teacup”, a phrase Mhlongo noted meant “a lot of unnecessary anger and worry about a matter that is not important”.
Even more astonishingly, the IEC labelled the expert’s complaint of these massive errors as “trumped up”, a term defined by Merriam-Webster (as cited by Mhlongo) as “fraudulently concocted”.
Instead of ordering a system audit, the IEC instructed the public to simply use “other results reporting functions on the website” to find the correct data.
Mhlongo utilised an interesting analogy to expose the absurdity of this defence: “Consider a situation in which several patrons have visited a restaurant that boasts extremely high standards of hygiene… When the dishes arrive, a few of the patrons notice flies in some of the main dishes… They call the restaurant owner and point out… ‘Sir, there are flies in the food!’”
Mhlongo continues, mapping the IEC’s response to an arrogant restaurant owner who insists the patrons are not food experts, calls the complaint a “storm in a teacup”, and tells them to “just eat the main dishes and side dishes that don’t have any flies in them!”
Mhlongo’s verdict on this institutional defensiveness is clear: “Let me spell it out for you: Your restaurant is compromised!” He argued that the presence of these “flies” (the ubiquitous coding errors) proved that the entire kitchen (the core code and quality assurance processes) was fundamentally flawed.
An ICT system with proper quality assurance “will never result in tens of thousands of reports with grave errors in them, going completely undetected”.
The political and media narrative relies on the premise that the 2024 elections were managed by a trusted, fully audited, and technologically sound institution. The expert affidavits provided by Vusi Mhlongo dismantle this premise entirely, replacing it with a documented history of reckless system management, inadequate “rubber stamp” audits, and tens of thousands of mathematically impossible reports.
The IEC’s failure to conduct a comprehensive, line-by-line code audit of the live production system, combined with their dismissive attitude toward glaring data anomalies, leaves a void of transparency.
As Mhlongo concluded in both his founding and replying affidavits: “There is [unfortunately] no basis to conclude that the 2024 elections were free and fair without: (i) carrying out a detailed investigation into the IEC’s digital votes capturing and reporting system to assess the extent to which it is flawed; and (ii) moving to assess whether the aggregation and reporting on the 2024 elections carried out was accurate.”
Until the “flies in the food” are acknowledged and the underlying code is subjected to genuine, independent forensic scrutiny, the claims that the system is flawless remain, at best, a comforting illusion, and at worst, a deliberate obfuscation of a profound ICT crisis.
* Sizwe Dlamini is editor of the Sunday Independent.
** The views expressed here do not reflect those of the Sunday Independent, Independent Media, or IOL.