South Africa is facing a growing threat from cyberattackers, with several high-profile incidents reported in recent months. Over the past month, companies such as Hungry Lion, Bidvest Bank, the Furniture Bargaining Council, CarTrack, Serengeti Estates, and Toyota South Africa have all experienced cybersecurity breaches. This trend is expected to continue, with experts warning that the situation will only get worse. The Government Pensions Administration Agency (GPAA) suffered a cyberattack in February 2024, which forced a shutdown of all systems and resulted in a 668-gigabyte archive of sensitive data being published on a dark web leak site.

The GPAA breach highlighted the vulnerability of South Africa's critical infrastructure to cyberattacks. The Government Employees' Pension Fund (GEPF), which is the biggest pension fund on the continent, managing over R2.38-trillion in assets for 1.7 million active users, was initially forced to deny that a breach had occurred. However, after the sensitive data was published online, the GEPF was forced to admit that a breach had taken place. The incident resulted in a total system rebuild and significant delays in the processing of new retirements, resignations, and death benefits.

Experts point to a lack of investment in cybersecurity as a major factor contributing to South Africa's vulnerability. iGuardSA CEO Yugan Reddy, whose company was called in to help respond to the GPAA breach, noted that while South Africa has relatively advanced infrastructure, it is not protected. Reddy argued that the country's established infrastructure and connected systems make it an attractive target for cybercriminals, who use it as a testing ground for their attacks before launching them on more secure targets.

Reddy also highlighted the disparity in cybersecurity spending between government agencies and corporate entities. While corporate entities allocate around 15% of their IT budgets to cybersecurity, government agencies allocate less than 5%. This lack of investment, combined with a reliance on outdated systems and inexperienced engineers, has left government agencies particularly vulnerable to cyberattacks. Reddy also noted that basic cybersecurity frameworks and hygiene principles are often absent in state IT environments.

The South African government has been criticized for its lack of policy and enforcement tools to address the growing threat of cyberattacks. The government has been accused of outsourcing security to foreign OEMs and cloud vendors rather than investing in and cultivating local cybersecurity talent. This has resulted in targeted attacks on South African government entities, driven in part by xenophobic attacks and the country's genocide case against Israel at the International Court of Justice.

The rise of artificial intelligence (AI) has also introduced new challenges for cybersecurity experts. Reddy described AI as a "nightmare" for the industry, as threat actors use automated AI discovery tools to scan for zero-day vulnerabilities and build functional exploits within seconds. Defenders have little lead time to patch or configure defenses against never-before-seen vectors, making it increasingly difficult to protect against cyberattacks.

According to data from the Sophos State of Ransomware 2026 Reports, South Africa's security posture is not as bad as expected, but still concerning. Around 47% of South African victims cited a complete lack of protection as their operational root cause, while 85% of South African victims confirmed that their ransomware breach was directly linked to their most significant identity compromise. Communications Minister Solly Malatsi has announced that a new AI policy will be ready by March 2027, but it remains to be seen whether this will be enough to address the growing threat of cyberattacks.

Key points

  • South Africa's vulnerability to cyberattacks is driven by a lack of investment in cybersecurity, outdated systems, and inexperienced engineers.
  • The country's established infrastructure and connected systems make it an attractive target for cybercriminals.
  • Experts warn that the situation will only get worse unless the government takes steps to address the growing threat of cyberattacks.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.