Could Foreign Intelligence Exploit South Africa’s Security Weaknesses?
The Anyamba case raises a prudent counter-intelligence question: are South Africa’s institutions resilient to modern proxy recruitment?
Written By: Mthulisi Shongwe
When Portia Anyamba pleaded guilty in a Tennessee courtroom, the framing in most coverage was straightforward: a former SA Air Force brigadier general, working inside a US Department of Energy facility, had acted as an agent for South Africa’s own State Security Agency and had lied on her US security clearance forms about her contact with an SSA officer based at the South African embassy in Washington. This is, on its face, a story about South Africa spying on an ally, not about South Africa being infiltrated by anyone else.
I want to be upfront about that, because it would be intellectually dishonest to suggest otherwise. Nothing in the charging documents or the plea implicates Iran and I’m not going to pretend they do. But the case is worth sitting with for a different reason: it is a rare, court-verified window into how South Africa’s security cluster actually behaves when it is put under pressure to produce results, who gets tasked, how loosely, and with what oversight.
It is only one case, and no single prosecution can prove systemic institutional failure. But it is one of the few public cases that offers an unusually clear glimpse into how sensitive tasking and oversight function when exposed to judicial scrutiny. And once you look at that picture honestly, a harder question opens up: if the SSA was willing to run an operation this exposed against a treaty ally, using a serving general with access to a national laboratory, what does that say about whether the same institutional environment could be attractive to someone else entirely?
That question matters right now because Iran’s own external operations doctrine has changed in ways that are extremely well documented, and almost none of it looks like what people picture when they hear “Iranian spy.” Since the 2018 foiled bomb plot outside Paris ended in an Iranian diplomat’s conviction, Tehran’s Revolutionary Guard Corps and Ministry of Intelligence have shifted hard toward proxy recruitment, deliberately building distance between Iranian officials and the people who actually carry out the work.
MI5’s Director General has told Parliament that Iran has been linked to at least twenty potentially lethal plots on British soil since 2022 alone, and that the IRGC now routinely works through “criminals as proxies” from international drug traffickers to low-level crooks, rather than trained intelligence officers. In France and Germany, investigators found Iranian handlers working through drug traffickers based inside Iran, who in turn hired local European criminals to photograph and surveil Jewish targets for a few thousand euros each. In Sweden, established gangs including Foxtrot and Rumba have been accused of carrying out attacks against Israeli interests at Tehran’s direction.
Germany saw the IRGC contract a fugitive biker-gang boss to organise attacks on synagogues. Analysts who track this activity call the emerging pattern “proxy-of-a-proxy”: foreign nationals recruiting other foreign nationals, sometimes without either fully understanding who is ultimately directing them, with tasking and payment increasingly moved onto encrypted apps and cryptocurrency to keep Tehran’s fingerprints off the operation entirely. There are documented cases of teenagers being recruited online for surveillance and low-level sabotage work, apparently unaware of the chain above them.
It is also worth noting what this model is and what it is not. Tehran’s preferred approach is increasingly not to recruit serving military officers or intelligence officials directly, but to exploit people on the periphery: organised crime, commercial facilitators, ideological sympathisers, online recruits, and individuals whose access or proximity makes them useful without necessarily making them aware of the broader operation. The objective is not necessarily penetration at the highest levels, but the construction of deniable networks through successive layers of intermediaries.
None of this is a Middle Eastern curiosity happening far from South Africa’s concerns. Iranian intelligence interest in African soil isn’t new either. Israel’s embassy in Nairobi warned Kenyan authorities as far back as 2013 that Iran and Hezbollah were actively gathering intelligence on Israeli and Jewish targets across the region, South Africa included in the broader sweep of concern. South Africa, for its part, sits in a genuinely unusual position.
It maintains warm diplomatic and economic relations with Tehran, has consistently opposed unilateral Western sanctions on Iran, and through BRICS and its broader South-South foreign policy orientation has cultivated exactly the kind of environment in which Iranian diplomatic, commercial and political engagement is unusually extensive. None of that implies improper conduct. But countries that maintain broad networks of legitimate engagement can also present wider opportunities for hostile actors seeking cover, access or facilitation. A country doesn’t need to be an adversary’s target to become its access point; sometimes it’s simply the friendliest door in the building.
So here is the uncomfortable version of the question I think this moment demands: if Iran’s preferred model is now to recruit through cut-outs who may not even know who they’re really working for, and if South Africa’s own security cluster has just demonstrated, in open court, that it was capable of running an operation whose governance ultimately collapsed into criminal prosecution abroad, why would anyone assume that vulnerability is exclusive to operations South Africa itself initiates?
I’m not claiming there is a known Iranian cell inside South Africa’s security cluster; there is no such evidence on the public record, and I won’t manufacture the appearance of some. Nor am I suggesting that the Anyamba case proves South Africa’s institutions are systematically compromised. What I am saying is that it provides one rare, evidence-based opportunity to examine how vetting, oversight and accountability function under pressure. Those are precisely the kinds of institutional characteristics that hostile intelligence services assess when deciding where opportunities may exist. If Iran’s documented proxy model is built around identifying environments where oversight is weakest, then asking whether South Africa has adequately stress-tested its own institutions against that threat model is not an accusation. It is a prudent counter-intelligence question.
There’s a decolonial dimension to this worth naming honestly, too. It would be easy, and it’s a trap I want to avoid, to reach for “foreign infiltration” as a reflexive explanation the moment something embarrassing happens to South African institutions, the same reflex I’ve criticised elsewhere when it’s aimed at movements like March and March. The difference here is that I’m not asserting infiltration has happened. I’m asking whether the country’s institutions are actually resilient to a specific, externally documented method, using a real case as the diagnostic rather than the accusation.
That’s the audit I’d want the security cluster’s oversight committees to actually run, not “was Anyamba an Iranian asset” (she wasn’t, and saying so does nobody any favours), but “given what this case reveals about our own vetting, tasking and oversight, have we adequately assessed whether our institutions are resilient to the kinds of proxy recruitment models that hostile intelligence services are now demonstrably using elsewhere?” It’s a fair question. More importantly, it’s a question that extends well beyond Iran. The Anyamba case ultimately tells us less about who South Africa was spying on than about the importance of ensuring our own institutions are resilient against anyone seeking to exploit the same vulnerabilities in future. I don’t think anyone currently in a position to answer that has been asked.
Mthulisi Shongwe is a former student leader and community activist with a background in international relations and political commentary. His interests include geopolitics, with a focus on the Middle East, China–South Africa relations and Sudan.


