Security2.06.2026

SABS executives in trouble after a crippling cyberattack

The Department of Trade has taken disciplinary action against two executives for failing to implement cybersecurity recommendations at the South African Bureau of Standards (SABS) in 2022.

As a result, the SABS systems were left vulnerable and ultimately suffered a cyberattack in November 2024.

The department recently provided Parliament with an update on the steps taken in response to the incident.

Private contractor TSU Protective Services was contracted to investigate and found that the relevant SABS executives should be held accountable.

Its investigation found they had failed to implement recommendations from the Auditor-General of South Africa and the State Security Agency from 2022.

“The board has noted the recommendation, and disciplinary action is being taken against the affected executives,” the department said.

“Charges have been proffered on 14 May 2026, and the disciplinary hearing has been scheduled for the first week of June 2026.”

The department said that, through its disciplinary processes, another employee was served with an official notice of allegations against them regarding the incident.

They responded, and a progressive discipline approach was implemented. It added that the suspensions of two other employees were lifted following the outcome of their disciplinary hearings.

The November 2024 hack on the SABS was one of the most severe and disruptive ransomware incidents to hit a South African state-owned entity.

“On 20 November 2024, the SABS suffered a significant cybersecurity incident involving a ransomware attack,” the department said in a presentation responding to allegations against the SABS.

“This attack has had serious implications for the SABS’s operational capabilities and its ability to deliver essential services.”

The department said SABS’s management activated business continuity plans to rebuild virtual machines, which concluded on 29 December 2024.

It said SABS was in the process of rebuilding its virtual machines, which would enable it to reinstall business applications.

SABS completely locked out of systems

SABS offices in Pretoria.

The cyberattack reportedly impacted the SABS’s salary systems, which became inaccessible, forcing it to pay November 2024 salaries manually.

At the time, SABS said an investigation had confirmed that its data had been encrypted, affecting its ICT systems.

The Lynx Ransomware Group, which has a reputation as a highly organised outfit with a structured affiliate programme and robust encryption methods, engineered the attack.

By February 2025, SABS and the Department of Trade, Industry, and Competition were still locked out of the affected systems.

Commenting on the news that systems remained encrypted, Democratic Alliance MP Toby Chance said it showed the extent to which the SABS was unprepared for such an incident.

“The SABS was unprepared for the attack it suffered at the hands of professional cybercriminals, who had clearly targeted it because of a failure to implement cybersecurity,” he said.

“Because of a failure to pay a service provider, its financial systems are still not operating, leading to invoices not being issued and a potential loss of income as the organisation battles to retain customers.”

While the Lynx Ransomware Group demanded a multi-million-rand ransom to decrypt the SABS’s systems, neither the organisation nor its controlling department has paid any ransom to date.

The department maintained a strict stance against paying ransoms, and the Lynx Ransomware Group refused to decrypt the SABS’s primary data and backup servers without payment.

The resulting near-total operational paralysis for an extensive period forced SABS to rebuild its digital infrastructure from scratch.

Show comments

Latest news

More news

Trending news

Poll

Which operating system do you have installed on your personal computer?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter