South Africa has experienced a series of high-profile ransomware attacks in recent months, with companies such as Cartrack, EasyEquities, and Satrix confirming breaches. Cartrack reported a ransomware attack on August 26, which was believed to have been carried out by the Dire Wolf group. The group claimed to have stolen 500GB of data, mostly related to American customers. These incidents have sparked concerns about the country's cyber security and its potential vulnerability to state-sponsored cyber operations.

While the recent incidents appear to be ordinary extortion, experts warn that they may be part of a larger issue. Nathan-Ross Adams, founder of ITLawCo and the South African Technology and Economic Competitiveness Initiative, argues that South Africa's cyber problem is not just about crime, but also about the country's ability to distinguish between ordinary cybercrime and strategic operations. He notes that the public record of the incidents does not necessarily prove anything geopolitical, but rather raises questions about the country's preparedness for potential state-sponsored cyber threats.

One of the incidents that has raised concerns is the breach at Air Traffic and Navigation Services (ATNS), which is investigating a ransomware incident in an operational-technology environment supporting weather-related air-traffic services. Preliminary findings indicate that there may have been exfiltration to IP addresses located in China, although this does not necessarily mean that the Chinese government was involved. ATNS is also dealing with an allegation of employee data theft, although initial inquiries have not substantiated this claim.

The concept of "cyberwarfare" may be misleading, according to experts. Thomas Rid has argued that cyberwar will not take place, and that the consequential activity sits between crime and war, in espionage, subversion, and sabotage. The Tallinn Manual 2.0, a non-binding expert analysis of international law in cyberspace, works through 79 rules on sovereignty, state responsibility, and international peace and security. These rules highlight the complexities of attributing cyber operations to states and the need for a nuanced approach to cyber security.

Cyberpersistence theorists argue that states compete through continuous campaigns whose effects accumulate below the armed-attack threshold. This means that states may be involved in cyber operations that are not necessarily part of a traditional war. Tim Maurer notes that states often delegate operations to proxies, orchestrate them through looser support, or sanction them by knowingly tolerating activity they could stop. This blurs the line between crime and state-sponsored cyber operations.

South Africa has already seen political grievance turn digital, with a campaign by Nigerian-linked hacktivist groups claiming attacks on several government agencies and companies in May. The country's foreign policy has created intelligence interest, particularly given its role as an applicant against Israel at the International Court of Justice and its membership of BRICS. However, there is no public evidence that any state is behind the recent incidents, and naming one would turn a security question into a conspiracy theory.

Henry Farrell and Abraham Newman offer a structural lens for understanding the country's cyber security challenges. They note that states that control the hubs of asymmetric global networks can use that position to watch and to coerce. For South Africa, the question is which financial, communications, cloud, and identity networks run through foreign-controlled hubs through which strategically valuable information or leverage could flow. The country's ability to attribute cyber operations and take action to prevent them will depend on its ability to understand these networks and the risks they pose.

Key points

  • The recent ransomware attacks in South Africa may be part of a larger issue, with experts warning that the country needs to be prepared for potential state-sponsored cyber threats.
  • The country's cyber security challenges are complex, with blurred lines between crime and state-sponsored cyber operations.
  • South Africa's foreign policy has created intelligence interest, particularly given its role as an applicant against Israel at the International Court of Justice and its membership of BRICS.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.