Cyberattack on South Africa’s pension fund shut down systems for four months — Daily Maverick
In South Africa, a cyberattack on the Government Pensions Administration Agency (GPAA), which administers the Government Employees’ Pension Fund (GEPF), led to a complete shutdown of information systems in February 2024. The platforms were restored only on June 21, 2024, after a complete rebuild of the system infrastructure, Daily Maverick reports.
According to the publication, the LockBit 3.0 group was behind the attack. The attackers may have gained access to the GPAA’s Windows environment through unpatched vulnerabilities on the network perimeter or compromised credentials. Initially, the GEPF said only that there had been an attempted intrusion and assured that the data had not been affected. Later, LockBit published a 668 GB archive containing records on 168,000 people on its darknet leak site, after which the fund acknowledged the breach.
Payment delays and personnel decision
During the system outage, the processing of new applications for retirement, dismissal, and death-related payments was significantly delayed. Employees were forced to carry out some procedures manually. The GEPF is the largest pension fund on the continent: it manages assets worth more than 2.38 trillion rand for 1.7 million active users.
South African Finance Minister Enoch Godongwana dismissed GPAA chief executive Kedibone Madie following a disciplinary hearing. The publication also notes that the stolen records included President Cyril Ramaphosa’s personal information.
More current news is available on the UA.News Telegram channel Telegram.
Problems with protecting government systems
iGuardSA chief executive Johan Reddy said that his company was the first engaged by South Africa’s State Information Technology Agency (Sita) after the attack was discovered. According to him, government bodies spend less than 5% of their IT budgets on cybersecurity, while the corporate sector allocates about 15%. He also pointed to government institutions’ dependence on systems and applications created 20–30 years ago.
According to the Sophos State of Ransomware 2026 report, based on a survey of 2,158 cybersecurity executives, including 135 in South Africa, 47% of South African ransomware victims cited the complete absence of protection as the root cause of the incident. This was the highest figure among the 17 countries studied. Only 40% of South African companies resumed operations within a week after a cyberattack, compared with 55% globally. Another 13% of companies required between one and six months to restore their systems.
South African Communications Minister Solly Malatsi said that the country’s new artificial intelligence policy should be ready by March 2027.