Urgent.News

What's breaking now, across thousands of outlets.

World

DIGITAL SOVEREIGNTY: SA is under cyber siege — and the situation will only get worse

Over the past month, Hungry Lion, Bidvest Bank, the Furniture Bargaining Council, CarTrack, Serengeti Estates and Toyota South Africa all experienced cybersecurity incidents. South Africa doesn’t even have a national AI policy yet, but the loudest conversation at GovTech 2026 was about digital sovereignty.

DIGITAL SOVEREIGNTY: SA is under cyber siege — and the situation will only get worse

South Africa is currently facing a significant cybersecurity threat, with the country being targeted in a string of incidents over the past month. Key organizations that experienced cyber attacks include Hungry Lion, Bidvest Bank, the Furniture Bargaining Council, CarTrack, Serengeti Estates, and Toyota South Africa. Despite South Africa lacking a national AI policy, discussions surrounding digital sovereignty dominated the GovTech 2026 conference.

In February 2024, the Government Pensions Administration Agency (GPAA), which manages the Government Employees' Pension Fund (GEPF) – the biggest pension fund on the continent – was hit by a cyberattack. The attackers, identified as LockBit 3.0, exploited unpatched perimeter vulnerabilities or compromised credentials to breach the GPAA's Windows environment.

The Government Employees' Pension Fund initially denied the incident, claiming it had been an "attempted" intrusion. However, LockBit later published a 668-gigabyte archive containing records of 168,000 data subjects on its dark web leak site, forcing GEPF to admit to the breach.

The full infrastructure shutdown lasted until June 21, 2024, when systems were finally restored after a complete system rebuild. This incident severely delayed the processing of new retirements, resignations, and death benefits, forcing staff to handle tasks manually. The incident came just two months before the two-pot withdrawal system was set to go live, which occurred on September 1, 2024. During this period, 361,000 members withdrew R4.1 billion in rapid liquidity.

Finance Minister Enoch Godongwana dismissed GPAA CEO Kedibone Madiehe following a disciplinary hearing, but the situation highlighted the need for improved cybersecurity. iGuardSA CEO Yugan Reddy, whose company was among the first to be contacted by the State IT Agency (Sita) when the breach was discovered, explained that South Africa's advanced infrastructure, while decent, makes the country an attractive testing ground for cybercriminals.

He emphasized that while South Africa has established infrastructure, it is not adequately protected. Reddy also pointed out that government agencies rely on legacy systems and applications, often maintained by inexperienced engineers, and that basic cybersecurity frameworks and hygiene principles are largely absent in state IT environments.

Written by urgent.news from Daily Maverick's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dailymaverick.co.za →

More in World

GH Bank records H1 mortgage growth

During the first half of this year, new lending by the Government Housing (GH) Bank, a state financial institution specialising in mortgages, grew 15% year-on-year, with robust gains among low- and…

More from Tuesday 22 September →