MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Ransomware severely disrupts GPAA pension-benefits administration

South Africa's Government Pensions Administration Agency detected a security breach on 16 February 2024 and shut down its systems to contain the incident. Subsequent official reporting identified ransomware activity linked to LockBit 3.0 and described severe disruption to GPAA operations, particularly benefits administration, after critical files were encrypted. System restoration continued into April. The Government Employees Pension Fund stated that pension payments themselves were not affected, so the incident is classified on the basis of the documented disruption to pension administration rather than payment interruption.

80

Estimated severity

80 / 100

92

Source reliability

92 / 100

Approximate Date

16/02/2024

Targeted Company

GOVERNMENT PENSIONS ADMINISTRATION AGENCY

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

GOVERNMENT EMPLOYEES PENSION FUND (Business process outsourcer)

Geographic Impact

Country Targeted Company

South Africa

ZAF

Other Affected Countries

No other affected countries reported

Target country

South Africa

Affected countries

South Africa

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Operational disruptionService degradationService unavailability

Affected sectors

Government & Public AdministrationFinance & Insurance

Affected departments

Information TechnologyFinance

Attack Profile

Attack types

RansomwareData exfiltration

Attributed threat actors

LOCKBIT

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.