South African Pension Fund Systems Restored After Ransomware Attack
At a glance
- Ransomware attack hit GPAA systems on 16 February 2024.
- 168,000 data records were accessed during the breach.
- Full system restoration completed by 21 June 2024.
The Government Pensions Administration Agency (GPAA), which manages the Government Employees Pension Fund (GEPF) in South Africa, experienced a ransomware incident in February 2024 that disrupted its digital platforms for several months.
On 16 February 2024, the GPAA confirmed it was targeted by a ransomware attack attributed to the LockBit 3.0 group. In response, the agency took all its systems offline to contain the breach and prevent further access to sensitive information.
The shutdown affected the GEPF’s self-service portal and mobile application, which remained unavailable while the agency worked on a complete rebuild of the affected systems. Restoration efforts continued for several months, with the agency stating that platforms would be operational again by 21 June 2024.
During the incident, the GPAA initially communicated that no data breach had occurred. This position was revised after LockBit released data on 11 March 2024, confirming that unauthorized access had taken place.
What the numbers show
- 168,000 data subjects’ records were accessed during the breach.
- Systems were offline from 16 February to 21 June 2024.
- System restoration was largely completed by April 2024.
The agency engaged external cybersecurity firms Vodacom and IGuardSA to assist with the response and set up a Cybersecurity Recovery Steering Committee to coordinate recovery efforts. These actions were intended to address the technical and security challenges posed by the attack.
By April 2024, the GPAA reported that most systems had been restored, though work to fully remove threats from the network was still ongoing at that time. The agency maintained a full shutdown of its digital platforms until all systems were rebuilt and secured.
The full infrastructure was brought back online on 21 June 2024, marking the end of the shutdown period. The GPAA stated that the self-service portal and mobile app were once again accessible to users following this restoration.
LockBit 3.0 was identified as the group responsible for the ransomware attack, according to reports and agency statements. The incident affected a large number of data subjects and required extensive technical and organizational measures to resolve.
* This article is based on publicly available information at the time of writing.