The Information Regulator of South Africa said that it had recorded over 8,000 security breaches in the country since its inception.
The Information Regulator of South Africa said that it has recorded over 8,000 cybersecurity breaches in the country since its inception.
However, this total did not capture the full extent of the country’s cybercrime crisis, as a significant number of breaches are not reported to the regulator.
Information Regulator chairperson Pansy Tlakula shared the statistics during a recent media briefing, where she presented updates on ongoing investigations into POPIA contraventions.
Tlakula also gave updates on high-profile cases the regulator had been working on, as well as other challenges and insights on the current regulatory environment.
She said that South Africa was experiencing an increasingly hostile cybersecurity landscape, with data breaches exposing the personal information of millions of people.
“Public and private bodies that hold personal information are, in effect, entrusted with information that belongs to individuals (data subjects),” said Tlakula.
“When this information is compromised, the consequences can be devastating.”
In the five months from 1 April to date, the Information Regulator received 1,220 data breach notifications from companies in South Africa.
Tlakula said that if the trend continued, South Africa would have over 3,000 reported data breaches by the end of 2026.
“The consequences of a security compromise can extend well beyond the exposure of personal information,” she said.
“Depending on the depth, a security compromise can interrupt essential services, damage institutional credibility, undermine public confidence and have significant economic consequences.”
In the private sector, one of South Africa’s largest technology distributors, Rectron, experienced a particularly debilitating cyberattack in July.
A ransomware attack carried out by what was believed to be the Dragonforce extortion group knocked Rectron’s network offline and forced the company to cease operations for more than a week.
“As a result of the unauthorised access, data containing personal information was accessed and potentially exfiltrated,” Rectron said in a statement at the time.
“We commenced an investigation immediately with the assistance of external forensic specialists. We are taking the necessary steps to contain, assess and remediate the incident.”
The South African Bureau of Standards (SABS)
Tlakula announced that the South African Bureau of Standards (SABS) had been issued an Enforcement Notice from the regulator. The bureau suffered a crippling ransomware attack in 2024.
The cyberattack reportedly impacted the SABS’s salary systems, which became completely inaccessible, forcing the organisation to pay its November 2024 salaries manually.
SABS said at the time of the incident that its data had been encrypted and its ICT systems were significantly impacted.
The Lynx ransomware group claimed responsibility for the attack and demanded millions to decrypt the system, which the SABS did not pay.
SABS and the Department of Trade, Industry, and Competition were still locked out of affected systems four months later.
The resulting near-total operational paralysis forced the SABS to rebuild its digital infrastructure from scratch and led to disciplinary action against two of the organisation’s executives.
Following the attack and system encryption at the SABS, the Information Regulator initiated its own assessment of the circumstances surrounding the breach.
“Following the completion of that assessment, we issued an Enforcement Notice against SABS. We found that they have violated the POPIA for lawful processing of personal information,” said Tlaluka.
She said that the SABS was in breach for processing excessive, irrelevant information, using inadequate consent methods, having weak security safeguards, and failing to address known vulnerabilities.
Further, the organisation was found not to have had an incident response plan in place, and it failed to inform data subjects of its data collection methods, among other breached conditions.
The regulator instructed SABS to improve its security and data protection practices within 90 days of the receipt of the Enforcement Notice.
Failure to do so would result in a significant fine imposed on the organisations, which have reached up to R5 million in the past.