Friday, 9 October 2026 SourcesAbout🌓
🇿🇦 ZA ▾
BREAKING
Latest

DIGITAL SOVEREIGNTY: SA is under cyber siege — and the situation will only get worse

Daily Maverick ·
DIGITAL SOVEREIGNTY: SA is under cyber siege — and the situation will only get worse

Over the past month, Hungry Lion, Bidvest Bank, the Furniture Bargaining Council, CarTrack, Serengeti Estates and Toyota South Africa all experienced cybersecurity incidents. South Africa doesn’t even have a national AI policy yet, but the loudest conversation at GovTech 2026 was about digital sovereignty.

In February 2024, the Government Pensions Administration Agency (GPAA) – the admin for the Government Employees’ Pension Fund (GEPF) – suffered a cyberattack that forced a shutdown of all systems.

A threat actor, later revealed as LockBit 3.0, breached the GPAA’s Windows environment via unpatched perimeter vulnerabilities or compromised credentials.

Initially, the GEPF (the biggest pension fund on the continent, managing more than R2.38-trillion in assets for 1.7 million active users) denied that it happened, publicly stating that an “attempted” intrusion had occurred, but assuring the public that no data were compromised.

Then LockBit published a 668-gigabyte archive containing records of 168,000 data subjects on its new dark web leak site, and GEPF finally admitted the breach, stating the GPAA had misinformed it.

The complete infrastructure shutdown persisted until 21 June 2024, when platforms were finally brought back online after a total system rebuild. The processing of new retirements, resignations and death benefits was severely delayed, forcing staff to attempt the tasks manually.

That was two months before the two-pot withdrawal system was due to go live – which happened on 1 September 2024, and 361,000 members withdrew R4.1-billion in rapid liquidity.

Finance Minister Enoch Godongwana dismissed GPAA CEO Kedibone Madiehe after a disciplinary hearing this month, but the entire saga taught the newly formed Government of National Unity a lesson in cybersecurity.

iGuardSA CEO Yugan Reddy, whose company was the first that the State IT Agency (Sita) called when the breach was discovered, explained the sequence of events to Daily Maverick at GovTech 2026 .

He agrees that South Africa has had a rough time since, but refutes the notion that the country is merely passively susceptible, pointing out that its relatively advanced infrastructure makes it uniquely attractive to international attackers:

“We actually have some pretty good infrastructure. Our comms infrastructure is decent. A lot of our systems are developed, and the data is readily available via those systems. So what happens is we become a nice sort of testing ground for the cybercriminals. They almost use us to test a lot of their attacks before they launch them on a first world.”

He corrected himself immediately, because, in his assessment, over the past five years, attackers realised that South Africa is not only a testing ground but an easily monetisable victim pool.

“So we’ve got established infrastructure, everything’s connected, but it’s not protected,” he explained. “In a first-world country, everything's connected but protected. We are just nicely in between for them.

Read the full article on Daily Maverick ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.dailymaverick.co.za — the content belongs to Daily Maverick.

More from Daily Maverick

See all ›

More in Latest

See all ›