{
  "id": 9204870,
  "title": "DIGITAL SOVEREIGNTY: SA is under cyber siege — and the situation will only get worse",
  "url": "https://urgent.news/2026/09/22/digital-sovereignty-sa-is-under-cyber-siege-and-the-situation-will",
  "topic": "world",
  "section": "World",
  "published": "2026-09-22T21:56:40.000Z",
  "source": {
    "name": "Daily Maverick",
    "slug": "daily-maverick",
    "url": "https://www.dailymaverick.co.za/article/2026-09-22-sa-is-under-cyber-siege-and-the-situation-will-only-get-worse/"
  },
  "original_language": "en",
  "account": "South Africa is currently facing a significant cybersecurity threat, with the country being targeted in a string of incidents over the past month. Key organizations that experienced cyber attacks include Hungry Lion, Bidvest Bank, the Furniture Bargaining Council, CarTrack, Serengeti Estates, and Toyota South Africa. Despite South Africa lacking a national AI policy, discussions surrounding digital sovereignty dominated the GovTech 2026 conference.\n\nIn February 2024, the Government Pensions Administration Agency (GPAA), which manages the Government Employees' Pension Fund (GEPF) – the biggest pension fund on the continent – was hit by a cyberattack. The attackers, identified as LockBit 3.0, exploited unpatched perimeter vulnerabilities or compromised credentials to breach the GPAA's Windows environment. The Government Employees' Pension Fund initially denied the incident, claiming it had been an \"attempted\" intrusion. However, LockBit later published a 668-gigabyte archive containing records of 168,000 data subjects on its dark web leak site, forcing GEPF to admit to the breach.\n\nThe full infrastructure shutdown lasted until June 21, 2024, when systems were finally restored after a complete system rebuild. This incident severely delayed the processing of new retirements, resignations, and death benefits, forcing staff to handle tasks manually. The incident came just two months before the two-pot withdrawal system was set to go live, which occurred on September 1, 2024. During this period, 361,000 members withdrew R4.1 billion in rapid liquidity.\n\nFinance Minister Enoch Godongwana dismissed GPAA CEO Kedibone Madiehe following a disciplinary hearing, but the situation highlighted the need for improved cybersecurity. iGuardSA CEO Yugan Reddy, whose company was among the first to be contacted by the State IT Agency (Sita) when the breach was discovered, explained that South Africa's advanced infrastructure, while decent, makes the country an attractive testing ground for cybercriminals. He emphasized that while South Africa has established infrastructure, it is not adequately protected. Reddy also pointed out that government agencies rely on legacy systems and applications, often maintained by inexperienced engineers, and that basic cybersecurity frameworks and hygiene principles are largely absent in state IT environments.",
  "summary": "Over the past month, Hungry Lion, Bidvest Bank, the Furniture Bargaining Council, CarTrack, Serengeti Estates and Toyota South Africa all experienced cybersecurity incidents. South Africa doesn’t even have a national AI policy yet, but the loudest conversation at GovTech 2026 was about digital sovereignty.",
  "key_points": [
    "South Africa faces significant cyber threats from various organizations.",
    "GPAA, managing the largest pension fund, suffered a cyberattack in February 2024.",
    "South Africa's cybersecurity is inadequate despite advanced infrastructure."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}