<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber attack Archives - ProtectionWeb</title>
	<atom:link href="https://www.protectionweb.co.za/tag/cyber-attack/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.protectionweb.co.za/tag/cyber-attack/</link>
	<description>First with Security News</description>
	<lastBuildDate>Fri, 19 Sep 2025 07:21:25 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://www.protectionweb.co.za/wp-content/uploads/2024/04/cropped-ProtectionWebLogo-512x512-1-32x32.png</url>
	<title>cyber attack Archives - ProtectionWeb</title>
	<link>https://www.protectionweb.co.za/tag/cyber-attack/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Over 100 000 cyber-attacks while SAPS records just 544 cases</title>
		<link>https://www.protectionweb.co.za/cyber-security/over-100-000-cyber-attacks-while-saps-records-just-544-cases/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/over-100-000-cyber-attacks-while-saps-records-just-544-cases/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Fri, 19 Sep 2025 07:21:18 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[Democratic Alliance]]></category>
		<category><![CDATA[Office of the Cyber Commissioner]]></category>
		<category><![CDATA[SAPS]]></category>
		<category><![CDATA[South African Police Service]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98629</guid>

					<description><![CDATA[<p>Over 100 000 banking breaches in 2024 caused R1.8 billion in losses, yet the South African Police Service (SAPS) recorded only 544 cases. This is according to the Democratic Alliance (DA), which said it has consequently tabled a Private Members Bill establishing a new Chapter 9 Institution in the form of the Office of the [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/over-100-000-cyber-attacks-while-saps-records-just-544-cases/">Over 100 000 cyber-attacks while SAPS records just 544 cases</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Over 100 000 banking breaches in 2024 caused R1.8 billion in losses, yet the South African Police Service (SAPS) recorded only 544 cases.</p>
<p>This is according to the Democratic Alliance (DA), which said it has consequently tabled a Private Members Bill establishing a new Chapter 9 Institution in the form of the Office of the Cyber Commissioner.</p>
<p>While the response from the private sector and academia was overwhelmingly positive, the Bill’s reception in government and the public sector was predictably less positive, said Advocate Glynnis Breytenbach, DA Spokesperson on Justice and Constitutional Development.</p>
<p>Nevertheless, as the cyber-attacks on the country and our institutions increase daily, and the costs attached thereto continue to escalate, it remains a piece of legislation that requires serious consideration, Breytenbach said.</p>
<p>It appears from police statistics that they have only 544 cyber related fraud cases on their register, yet in excess of 100 000 cyber-attacks on banking accounts occurred in the 2024 year, according the SABRIC. This represents a loss of around R1.8 billion to individuals and represents an 86% increase in such attacks from the previous year.</p>
<p>“Clearly, there is a distinct problem in the fact that the SAPS have so few matters under investigation while the actual attacks have almost doubled. This again underlines the fact that we are in no position to deal effectively with the risk of cybercrime in South Africa. Our country is targeted precisely because of our inadequate structures set up to deal with this issue,” Breytenbach continued.</p>
<p>“The SAPS are underfunded, under-resourced and under trained. The Information Regulator is not adequately resourced nor equipped to deal with all these occurrences, and cyber criminals are having a field day.</p>
<p>“It is clear that some proactive steps must be taken urgently to revisit this issue, and we will continue to press ahead with this piece of legislation, designed to deal with cyber-crime, cyber-attacks and protocols in a more pro-active fashion,” Breytenbach concluded.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/over-100-000-cyber-attacks-while-saps-records-just-544-cases/">Over 100 000 cyber-attacks while SAPS records just 544 cases</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/over-100-000-cyber-attacks-while-saps-records-just-544-cases/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DDoS attacks continue to dominate the digital battlefield, destabilising critical infrastructure</title>
		<link>https://www.protectionweb.co.za/cyber-security/ddos-attacks-continue-to-dominate-the-digital-battlefield-destabilising-critical-infrastructure/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/ddos-attacks-continue-to-dominate-the-digital-battlefield-destabilising-critical-infrastructure/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Fri, 19 Sep 2025 07:20:27 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[distributed denial-of-service]]></category>
		<category><![CDATA[NETSCOUT]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98630</guid>

					<description><![CDATA[<p>Distributed Denial-of-Service (DDoS) attacks have evolved into precision-guided weapons of geopolitical influence capable of destabilising critical infrastructure, Netscout Systems has said in a new report that tracked over 8 million DDoS attacks in the first half of 2025. Of the 8 million attacks, 3.2 million were monitored in Europe, the Middle East and Africa (EMEA). [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/ddos-attacks-continue-to-dominate-the-digital-battlefield-destabilising-critical-infrastructure/">DDoS attacks continue to dominate the digital battlefield, destabilising critical infrastructure</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Distributed Denial-of-Service (DDoS) attacks have evolved into precision-guided weapons of geopolitical influence capable of destabilising critical infrastructure, Netscout Systems has said in a new report that tracked over 8 million DDoS attacks in the first half of 2025.</p>
<p>Of the 8 million attacks, 3.2 million were monitored in Europe, the Middle East and Africa (EMEA). Hacktivist groups like NoName057(16) orchestrated hundreds of coordinated strikes each month, targeting the communications, transportation, energy, and defence sectors. DDoS-for-hire services have democratised attack tools, enabling novice actors to execute sophisticated attack campaigns. AI-enhanced automation, multi-vector attacks, and carpet bombing techniques challenge traditional defences. Botnets compromised tens of thousands of IoT devices, servers, and routers, delivering sustained attacks and causing significant disruption.</p>
<p>While each of these elements is dangerous on its own, in aggregate, they have formed the perfect storm, creating unprecedented cyber risk for organisations and service provider networks around the world, Netscout said.</p>
<p>The company observed more than 50 attacks greater than a terabit-per-second (Tbps) and multiple gigapacket-per-second (Gpps) attacks in the first half of 2025, including a 3.12 Tbps attack in the Netherlands and a 1.5 Gpps attack in the United States.</p>
<p>The India-Pakistan conflict saw hacktivist groups target the Indian government and financial sectors in May, while the Iran-Israel conflict generated more than 15,000 attacks against Iran and 279 against Israel in June.</p>
<p>More than 880 bot-driven DDoS attacks occurred daily in March, peaking at 1,600 incidents, with attack durations increasing to an average of 18 minutes.</p>
<p>Leveraging DDoS-for-hire infrastructure, DieNet orchestrated over 60 attacks since March, while Keymous+ launched 73 attacks across 28 industry sectors in 23 countries.</p>
<p>NoName057(16) maintained dominance, claiming more than 475 attacks in March alone, 337% more than the next most active group. The hacktivist group targeted government websites in Spain, Taiwan, and Ukraine.</p>
<p>“As hacktivist groups leverage more automation, shared infrastructure, and evolving tactics, organizations must recognize that traditional defences are no longer sufficient,” stated Richard Hummel, director, threat intelligence, Netscout. “The integration of AI assistants and the use of large language models (LLMs), such as WormGPT and FraudGPT, escalates that concern. And, while the recent takedown of NoName057(16) was successful in temporarily reducing the group’s DDoS botnet activities, preventing a future return to the top DDoS hacktivist threat is not guaranteed. Organisations need intelligence-driven, proven DDoS defences that can deal with the sophisticated attacks we see today.”</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/ddos-attacks-continue-to-dominate-the-digital-battlefield-destabilising-critical-infrastructure/">DDoS attacks continue to dominate the digital battlefield, destabilising critical infrastructure</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/ddos-attacks-continue-to-dominate-the-digital-battlefield-destabilising-critical-infrastructure/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A targeted attack mimics communication from company CEO to steal funds</title>
		<link>https://www.protectionweb.co.za/cyber-security/a-targeted-attack-mimics-communication-from-company-ceo-to-steal-funds/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Mon, 09 Jun 2025 09:38:55 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97996</guid>

					<description><![CDATA[<p>Over the last few weeks, Kaspersky detected a series of sophisticated attack attempts aimed at deceiving an organisation’s finance team into paying fraudulent invoices. Emails mimicking correspondence between the organisation’s CEO and contractor companies were sent to the organisation’s finance department to persuade them into paying urgent “invoices” for alleged “consulting services”. These attack attempts [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/a-targeted-attack-mimics-communication-from-company-ceo-to-steal-funds/">A targeted attack mimics communication from company CEO to steal funds</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span lang="en-US" data-olk-copy-source="MessageBody">Over the last few weeks, Kaspersky detected a series of sophisticated attack attempts aimed at deceiving an organisation’s finance team into paying fraudulent invoices. Emails mimicking correspondence between the organisation’s CEO and contractor companies were sent to the organisation’s finance department to persuade them into paying urgent “invoices” for alleged “consulting services”. These attack attempts highlight <span data-ogsc="black">a disturbing trend</span> of targeted schemes leveraging forged executive identities to exploit corporate trust.</span><u></u><u></u></p>
<p><span lang="en-US">The analysed attack attempts were examples of business email compromise (BEC) attacks. As a rule, such attacks are made on behalf of a management representative of a compromised firm. Importantly, in all analysed cases the senders were fake – the real addresses from where the emails came had nothing in common with the displayed sender names. These tricks were used to persuade the victims that the emails were legitimate.</span><u></u><u></u></p>
<p><span lang="en-US">Some incidents involved emails that imitated correspondence between the company’s CEO and an alleged contractor law firm, urging the financial department to pay the attached fake invoice. The fake correspondence with the CEO of a victim company was used as “proof” that the request for payment was legitimate. In this attack the name of the fictional partner company was indicated only in the <i>name of the sender</i> field, and a real email address was different and changed from email to email.</span><u></u><u></u></p>
<p><span lang="en-US">Other incidents featured similar emails that mimicked communications between the CEO and contractor companies to request urgent payment for a fake invoice, but this time the invoice itself was not attached.</span><u></u><u></u></p>
<p><span lang="en-US">“This attack stands out for its meticulous attention to detail and exploitation of trusted relationships. By fabricating convincing email threads and impersonating high-level executives, attackers are banking on employees’ reluctance to question seemingly authentic requests. Companies must prioritise employee training and robust email verification systems to counter these evolving threats,” commented Anna Lazaricheva, spam analyst at Kaspersky.</span><u></u><u></u></p>
<p><span lang="en-US">In order to avoid becoming a victim of fraudulent messages and specifically business email compromise attacks, Kaspersky experts advise the following:</span><u></u><u></u></p>
<ul type="disc">
<li><span lang="en-US">Check the sender&#8217;s email address and do not rely on the displayed name of the sender, as actual email addresses may have nothing in common with the companies and people who are displayed to have sent the email.</span><u></u><u></u></li>
<li><span lang="en-US">Only open emails and click links if you are sure you can trust the sender; make sure that the sender’s address is legitimate.</span><u></u><u></u></li>
<li><span lang="en-US">When a sender is legitimate, but the content of the message seems strange, it is worth checking with the sender via an alternative means of communication.</span><u></u><u></u></li>
<li><span lang="en-US">Check the spelling of a website’s URL if you suspect you are faced with a phishing page. The URL may contain mistakes that are hard to spot at first glance, such as a 1 instead of I or 0 instead of O.</span><u></u><u></u></li>
<li><span lang="en-US">Use a proven cybersecurity solution such as Kaspersky Next and Kaspersky Premium when surfing the web.</span><u></u><u></u></li>
</ul>
<p><b><span lang="en-US" data-ogsc="black"> </span></b></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/a-targeted-attack-mimics-communication-from-company-ceo-to-steal-funds/">A targeted attack mimics communication from company CEO to steal funds</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>South African Airways hit by major cyber attack</title>
		<link>https://www.protectionweb.co.za/cyber-security/south-african-airways-hit-by-major-cyber-attack/</link>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Thu, 08 May 2025 07:01:26 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[SAA]]></category>
		<category><![CDATA[South African Airways]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97773</guid>

					<description><![CDATA[<p>South African Airways (SAA) has confirmed that it experienced a significant cyber incident starting on Saturday, 3 May, which temporarily disrupted access to its website, mobile app, and several internal operational systems. Upon detecting the breach, SAA immediately activated its disaster management and business continuity protocols. These swift measures contained the incident effectively, minimising disruption [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/south-african-airways-hit-by-major-cyber-attack/">South African Airways hit by major cyber attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>South African Airways (SAA) has confirmed that it experienced a significant cyber incident starting on Saturday, 3 May, which temporarily disrupted access to its website, mobile app, and several internal operational systems.</p>
<p>Upon detecting the breach, SAA immediately activated its disaster management and business continuity protocols. These swift measures contained the incident effectively, minimising disruption to core flight operations and ensuring that essential customer service channels, including contact centres and sales offices, remained operational. Normal system functionality was restored later the same day, SAA said in a statement.</p>
<p>SAA management launched a thorough investigation with independent digital forensic experts to determine the root cause and full scope of the incident, including the possibility of external cybercrime involvement. As a National Key Point, SAA has reported the incident to the State Security Agency (SSA), South African Police Service (SAPS), and notified the Information Regulator of South Africa under the Protection of Personal Information Act (POPIA).</p>
<p>The preliminary investigation is ongoing to assess whether any data was accessed or exfiltrated. SAA has committed to notifying any affected parties directly, in line with regulatory requirements, should a data breach be confirmed, the airline said.</p>
<p>&#8220;The security and integrity of our business systems and the protection of the consumer data entrusted to us remain our highest priority. In response to the cyber incident that began on May 3rd, we acted swiftly to contain the disruption, restore services, and initiate a comprehensive investigation. Our robust business continuity measures ensured operational stability, particularly for our valued customers. I want to assure all stakeholders, including our partners, customers, and dedicated employees, that we are taking every necessary step to determine the root cause of this incident, strengthen our security framework, and mitigate any potential risks. SAA remains committed to delivering safe, reliable, and resilient service,” said Prof John Lamola, Group CEO of SAA.</p>
<p>Over the past several years, South African government entities have faced a surge in cyberattacks, particularly ransomware, targeting critical infrastructure and disrupting key services. Notable incidents include the crippling of the Department of Justice and Constitutional Development’s IT systems in September 2021, a ransomware attack on Transnet in July 2021 that brought port operations to a near standstill, and repeated disruptions at the South African Post Office and South African National Space Agency.</p>
<p>More recently, the South African Weather Service was taken offline by a ransomware group in January 2025, impacting weather reporting for aviation and marine sectors. These attacks, often linked to sophisticated international cybercrime groups, have exposed vulnerabilities in government systems, sometimes exacerbated by insider involvement, and have led to significant operational disruptions, data breaches, and financial losses.</p>
<p>South Africa now averages thousands of cyberattacks per week against government agencies, making it one of the continent’s most targeted countries, with ransomware and information disclosure among the most prevalent threats.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/south-african-airways-hit-by-major-cyber-attack/">South African Airways hit by major cyber attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Securing Africa’s manufacturing sector against cybercrime</title>
		<link>https://www.protectionweb.co.za/opinion-and-analysis/securing-africas-manufacturing-sector-against-cybercrime/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Tue, 11 Feb 2025 06:53:51 +0000</pubDate>
				<category><![CDATA[Opinion and Analysis]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[manufacturing]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97237</guid>

					<description><![CDATA[<p>Connectivity and automation have undeniably revolutionised the manufacturing sector, boosting efficiency and productivity. However, they have also introduced significant vulnerabilities, leaving the industry increasingly exposed to cybersecurity threats. In fact, recent insights from Datacentrix partner, Check Point revealed that manufacturing emerged as the most impacted by cyberattacks in the third quarter of 2024, with the sector experiencing [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/opinion-and-analysis/securing-africas-manufacturing-sector-against-cybercrime/">Securing Africa’s manufacturing sector against cybercrime</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span lang="en-GB"><span data-ogsc="black" data-olk-copy-source="MessageBody">Connectivity and automation have undeniably revolutionised the manufacturing sector, boosting efficiency and productivity. However, they have also introduced significant vulnerabilities, leaving the industry increasingly exposed to cybersecurity threats.</span></span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB">In fact, recent insights from Datacentrix partner, </span><span lang="en-GB"><a title="https://blog.checkpoint.com/research/a-closer-look-at-q3-2024-75-surge-in-cyber-attacks-worldwide/" href="https://blog.checkpoint.com/research/a-closer-look-at-q3-2024-75-surge-in-cyber-attacks-worldwide/" data-auth="NotApplicable" data-linkindex="2" data-ogsc=""><span data-ogsc="">Check Point</span></a></span><span lang="en-GB"> revealed that manufacturing emerged as the most impacted by cyberattacks in the third quarter of 2024, with the sector experiencing 30 percent of all reported ransomware attacks globally over the period.<u></u><u></u></span></p>
<p><span lang="en-GB">Another concerning statistic was the fact that – at a regional level – Africa bore the brunt of cyber threats over the timespan, with local organisations facing an average of 3,370 attacks per week – an alarming 90 percent increase from the previous year.<u></u><u></u></span></p>
<p><span lang="en-GB">Cybercriminals are exploiting vulnerabilities within manufacturing supply chains, targeting not only the manufacturers themselves, but also suppliers, logistics providers and even critical infrastructure. This underscores the urgent need for robust, proactive cybersecurity measures within this sector.<u></u><u></u></span></p>
<p><span lang="en-GB">Attacks in manufacturing can originate from many sources, including energy suppliers, logistics providers and shop floor equipment. Methods could include:<u></u><u></u></span></p>
<ul type="disc">
<li><b><span lang="en-GB">Ransomware</span></b><span lang="en-GB">: Disrupting supplier operations and production schedules, leading to delays and financial losses.<u></u><u></u></span></li>
<li><b><span lang="en-GB">Phishing</span></b><span lang="en-GB">: Extracting sensitive information such as login credentials or financial data, which could be used to disrupt operations or steal intellectual property.<u></u><u></u></span></li>
<li><b><span lang="en-GB">Distributed Denial of Service (DDoS) attacks</span></b><span lang="en-GB">: Overwhelming IT infrastructure and causing reputational damage.<u></u><u></u></span></li>
<li><b><span lang="en-GB">Malware infiltration</span></b><span lang="en-GB">: Introducing compromised components or software into the supply chain, potentially disrupting operations or compromising safety.<u></u><u></u></span></li>
<li><b><span lang="en-GB">Industrial espionage</span></b><span lang="en-GB">: Targeting manufacturing processes or intellectual property for competitive advantage or resale on the black market.<u></u><u></u></span></li>
</ul>
<p><b><span lang="en-GB">Building a secure framework for manufacturing<u></u><u></u></span></b></p>
<p><span lang="en-GB">To address these challenges, global criteria such as the International Electrotechnical Commission’s (IEC) 62443 standards and the International Organization for Standardization’s (<span data-ogsc="rgb(16, 25, 49)" data-ogsb="white">ISO) 27001 standard for </span></span><span lang="en-GB" data-ogsc="rgb(33, 37, 41)">information security management systems (ISMS)</span><span lang="en-GB">have been developed. These frameworks promote comprehensive cybersecurity practices across the manufacturing value chain, encompassing development, production and distribution.<u></u><u></u></span></p>
<p><span lang="en-GB" data-ogsc="black">ISO 27001 helps organisations identify and address risks holistically, integrating people, policies and technology into their security strategies. The IEC 62443 series, tailored for operational technology (OT), specifies security requirements suited to industrial automation and control systems, which differ from traditional IT environments.</span><u></u><u></u></p>
<p><b><span lang="en-GB">Proactive cybersecurity measures<u></u><u></u></span></b></p>
<p><span lang="en-GB">To strengthen cybersecurity and comply with the related standards, South African manufacturing organisations should begin with a comprehensive risk assessment to pinpoint vulnerabilities. Datacentrix recommends adopting advanced cybersecurity technologies for both OT and IT environments, alongside regular workforce training, including non-IT employees, on security best practices.<u></u><u></u></span></p>
<p><span lang="en-GB">It’s also possible to perform offline cyber audits for new equipment, where shop floor equipment can be scanned at staging or pre-production planning and certified as virus, malware and configuration risk free at that time and place. Furthermore, PLC code protection offers advanced PLC versioning, code management, code backup and function block level deployment services. This removes IP from engineering workstations and puts code in secure locations that are easily backed up, restored and documented for compliance and audits.<u></u><u></u></span></p>
<p><b><span lang="en-GB">Securing manufacturing&#8217;s future<u></u><u></u></span></b></p>
<p><span lang="en-GB">Manufacturing plays a vital role in driving economic growth and innovation. To remain resilient against cyber threats, organisations within this industry must adopt a proactive and collaborative approach to cybersecurity. As a hybrid ICT systems integrator and managed services provider, Datacentrix is committed to equipping manufacturing businesses with the tools and expertise needed to strengthen their supply chains and safeguard their operations.</span></p>
<p>The post <a href="https://www.protectionweb.co.za/opinion-and-analysis/securing-africas-manufacturing-sector-against-cybercrime/">Securing Africa’s manufacturing sector against cybercrime</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber security survey paints bleak picture for South Africa</title>
		<link>https://www.protectionweb.co.za/cyber-security/cyber-security-survey-paints-bleak-picture-for-south-africa/</link>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Wed, 09 Oct 2024 09:32:55 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CSIR]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Information and Cybersecurity Centre]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=96159</guid>

					<description><![CDATA[<p>Half of organisations in South Africa reported multiple cyber security incidents in the last year, and the majority suffered at least one security breach, according to a new survey by the Council for Scientific and Industrial Research (CSIR) Information and Cybersecurity Centre. The CSIR in collaboration with the Cybersecurity Hub under the Department of Communication [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/cyber-security-survey-paints-bleak-picture-for-south-africa/">Cyber security survey paints bleak picture for South Africa</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Half of organisations in South Africa reported multiple cyber security incidents in the last year, and the majority suffered at least one security breach, according to a new <a href="https://www.csir.co.za/documents/cybersecurity-awareness-and-preparednesspdf">survey</a> by the Council for Scientific and Industrial Research (CSIR) Information and Cybersecurity Centre.</p>
<p>The CSIR in collaboration with the Cybersecurity Hub under the Department of Communication and Digital Technologies this week announced the release of four national cyber security surveys conducted at the end of the 2023/24 financial year. Over 300 responses were collected for each survey, resulting in a total of over 1200 individuals and organisations participating.</p>
<p>One of the key findings concerned the prevalence of cyber attacks: A significant 47% of organisations reported experiencing 1-5 cyber security incidents in the past year, underscoring the persistent threat landscape, the CSIR said.</p>
<p>A concerning 88% of participants admitted to suffering at least one security breach, with 90% of those organisations being targeted multiple times.</p>
<p>Malware and phishing attacks emerged as the most common cyber threats, with organisations reporting a high incidence of these attacks.</p>
<p>Only 32% of the respondents indicated that over half of their employees have received cyber security awareness training in the past year, indicating a serious gap in organisations’ seriousness in building cyber security awareness and culture.</p>
<p>A critical challenge identified by the surveys was the cyber security skills gap, with 63% of cyber security roles partially or fully unfilled. Retaining cyber security talent is another pressing issue, with 35% of professionals citing better offers, lack of training opportunities, and other factors as reasons for leaving their current positions.</p>
<p>Only 41% of the organisations are assessing and monitoring cyber threats on daily basis, indicating that majority of organisations are not prepared to deal with cyber threats which according to Telecom Review Africa, South Africa experiences almost over 20 million cyber security threats or attacks per month.</p>
<p>The CSIR found that financial institutions (88.0%) were considered the most important driver of the South African digital identity market. Over two-thirds mentioned both encryption and privacy technologies (71%) and biometrics (68%) as drivers, while half reported identity theft being a serious concern that can be addressed by digital identity.</p>
<p>Dr Jabu Mtsweni, Head of the CSIR Information and Cybersecurity Centre, emphasised the significance of these surveys, stating, &#8220;In today&#8217;s interconnected world, cyber security is a paramount concern. These national surveys provide a comprehensive assessment of our cyber security posture and highlight areas where we need to strengthen our defences as a country, and further they provide local and contextual research in this domain&#8221;.</p>
<p>Dr Kiru Pillay from the Cybersecurity Hub commented that while the integration of ICTs into daily life has greatly benefited society, increased digital connectivity also introduces significant risks, as cybercriminals exploit vulnerabilities in cyberspace. “Cyber security must therefore be prioritised as a strategic imperative across all aspects of governance and service delivery. Studies like these are crucial in helping us understand our current standing as a country and determine where we should focus our initiatives.”</p>
<p>Based on the survey findings, the CSIR recommends investing in cyber security infrastructure, education, and research; developing a skilled cyber security workforce; strengthening incident responses; improving digital identity; and fostering public-private partnerships.</p>
<p>The CSIR said it believes that by addressing these recommendations, South Africa can significantly improve its cyber security posture and protect its critical infrastructure and citizens from cyber threats.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/cyber-security-survey-paints-bleak-picture-for-south-africa/">Cyber security survey paints bleak picture for South Africa</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Eight reasons why your business may get hacked</title>
		<link>https://www.protectionweb.co.za/cyber-security/eight-reasons-why-your-business-may-get-hacked/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Mon, 09 Sep 2024 10:19:30 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[corporate espionage]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[South Africa]]></category>
		<category><![CDATA[stolen data]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=95783</guid>

					<description><![CDATA[<p>No matter how big or small, any business can be a target for cyber attackers. While some business owners think they&#8217;re too small to be noticed, the numbers tell a different story. In 2023 alone, over 343 million people fell victim to cybercrimes, and it doesn&#8217;t look like it&#8217;s slowing down. Any organisation, whether it&#8217;s [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/eight-reasons-why-your-business-may-get-hacked/">Eight reasons why your business may get hacked</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>No matter how big or small, any business can be a target for cyber attackers. While some business owners think they&#8217;re too small to be noticed, the numbers tell a different story. In 2023 alone, over 343 million people fell victim to cybercrimes, and it doesn&#8217;t look like it&#8217;s slowing down.</p>
<p>Any organisation, whether it&#8217;s in the private sector, public sector, or even a charity, can be hit by a cyberattack. Hackers don&#8217;t discriminate; they go after companies of all sizes. In fact, small businesses are targeted 43% of the time, but only 14% are ready to defend themselves.</p>
<p>“Understanding the commonalities between victims and knowing how hackers select their targets is crucial to developing strong cybersecurity defences,” says Warren Bonheim, Managing Director of Zinia, a leading IT technology group and Managed Services Provider.</p>
<p>“For most hackers, the main motivation behind their attacks is straightforward: money. That&#8217;s why they often use tactics like ransomware to blackmail their victims or phishing schemes to trick people into making fake payments. However, there are other reasons too.”</p>
<p>So, what makes your business a tempting target for hackers? Let&#8217;s break it down:</p>
<p><strong>Money and Information</strong></p>
<p>Most hackers are after one thing: money. They might target a business because of its financial worth or the valuable information it holds. “Personal data, like financial details and customer info, can be sold on the dark web,” says Bonheim. That&#8217;s why companies with a lot of customer data, like those in the financial services industry, are prime targets.</p>
<p><strong>Corporate Espionage</strong></p>
<p>Some hackers target businesses not just for money but for valuable information like trade secrets, intellectual property, or confidential plans. This stolen data can be sold to competitors or used to gain a market edge. Bonheim stresses that in some cases, hackers are even hired by rival companies to engage in corporate espionage, stealing product designs and strategic plans.</p>
<p><strong>Weak Security</strong></p>
<p>Hackers often go for businesses with weak cybersecurity. They know smaller and medium-sized companies may not have the best defences. They use tricks like pretending to be a trusted source or sending enticing offers to get employees to click on links or open malware-infected attachments.</p>
<p><strong>Causing Chaos</strong></p>
<p>Some hackers aren&#8217;t after money; they just want to cause disruption. They often target service providers or companies with many connections, aiming to create a domino effect of chaos. “By disrupting these businesses, they can affect a broader network, amplifying the impact of their actions,” he says.</p>
<p><strong>Website Attacks</strong></p>
<p>Websites built on platforms like WordPress with many plugins can be vulnerable to attacks. Hackers might exploit these weaknesses to take down the site and demand a ransom. Bonheim stresses that often, these cyber attackers seek multiple smaller payouts instead of a single large one, making it easier to pressure businesses into paying.</p>
<p><strong>Blackmailing Executives</strong></p>
<p>Hackers often target executives, as they have much to lose. By accessing sensitive information on their phones or social media accounts, hackers can blackmail them, threatening to release damaging information unless paid. This tactic leverages the personal and professional stakes involved, making it a potent tool for extortion.</p>
<p><strong>Personal Vendettas</strong></p>
<p>Sometimes, hackers are motivated by personal grievances. They might target someone or a company to settle a score. “Protect yourself by using strong passwords, enabling two-factor authentication, and being cautious of suspicious emails, he says.</p>
<p><strong>Opportunistic Attacks</strong></p>
<p>Not all attacks are targeted. Some hackers use bots to cast a wide net, looking for any vulnerable system they can find. They send phishing emails to trick employees into clicking on links, which can then be used to launch further attacks.</p>
<p>In the end, it&#8217;s not just the big companies at risk. Anyone can be a target. So, it&#8217;s crucial to stay vigilant and protect your business from potential threats.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/eight-reasons-why-your-business-may-get-hacked/">Eight reasons why your business may get hacked</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NHLS cyber attack could cost lives</title>
		<link>https://www.protectionweb.co.za/cyber-security/nhls-cyber-attack-could-cost-lives/</link>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Mon, 15 Jul 2024 10:58:11 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[DPWI]]></category>
		<category><![CDATA[NHLS]]></category>
		<category><![CDATA[South Africa]]></category>
		<category><![CDATA[SSA]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=95165</guid>

					<description><![CDATA[<p>A day after Minister in the Presidency, Khumbudzo Ntshavheni, last week assured South Africans cyber security was “receiving the necessary attention” a second incident with potentially far-reaching implications was made public. Ntshavheni was reacting to so-called “revelations” of at least R300 million lost to cyber theft at the Department of Public Works and Infrastructure (DPWI) [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/nhls-cyber-attack-could-cost-lives/">NHLS cyber attack could cost lives</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A day after Minister in the Presidency, Khumbudzo Ntshavheni, last week assured South Africans cyber security was “receiving the necessary attention” a second incident with potentially far-reaching implications was made public.</p>
<p>Ntshavheni was reacting to so-called “revelations” of at least R300 million lost to cyber theft at the Department of Public Works and Infrastructure (DPWI) over a 10 year period. In a statement she said a State Security Agency (SSA) investigation was ongoing with continuing support and advice to government departments on cyber security.</p>
<p>Next in line for SSA attention in this regard, according to Democratic Alliance (DA) Portfolio Health Committee member, Michelle Clarke, should be the National Health Laboratory Service (NHLS), a Department of Health (DoH) entity.</p>
<p>It assists with communicable diseases, occupational health and cancer surveillance in addition to providing diagnostic pathology services. It has specialised institutes including the National Institute for Communicable Diseases (NICD), which includes the National Cancer Registry (NCR), National Institute for Occupational Health (NIOH), Forensic Chemistry Laboratories (FCL) and SA Vaccine Producers Association (SAVP). NHLS has laboratories in all nine provinces and is seen as a critical component of South African government healthcare.</p>
<p>A cyber-attack on NHLS, Clarke said, “rendered critical data unusable, significantly disrupting delivery of essential health services”.</p>
<p>Unlike the DPWI allegations, where money was uppermost in the cyber thieves’ minds, the NHLS attack could be life threatening in certain instances.</p>
<p>The attack, attributed to a group going by the name BlackSuit, affects issuing of test results to clinicians. This delay, Clarke said, especially for life-threatening conditions such as TB and HIV, can have dire consequences for patients.</p>
<p>The NHLS has implemented alternative measures, including a critical test list to manage the workload and ensure urgent tests are prioritised. “However, routine tests are still being performed, albeit under strained conditions. The development of an electronic registration system for new samples and test results is a positive step, but the current manual communication of urgent results is not a sustainable solution,” Clarke said.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/nhls-cyber-attack-could-cost-lives/">NHLS cyber attack could cost lives</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NHLS apologises for blood result delays following cyber attack</title>
		<link>https://www.protectionweb.co.za/cyber-security/nhls-apologises-for-blood-result-delays-following-cyber-attack/</link>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Thu, 04 Jul 2024 11:53:29 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[National Health Laboratory Service]]></category>
		<category><![CDATA[NHLS]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=95084</guid>

					<description><![CDATA[<p>The National Health Laboratory Service (NHLS) has said that while all its laboratories are operational following a cyber-attack, the issuing of test results to clinicians remains an issue. “Under normal circumstances, the laboratory reports are automatically generated and sent to clinicians or made available on WebView, this incident has disabled that functionality. However, all urgent [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/nhls-apologises-for-blood-result-delays-following-cyber-attack/">NHLS apologises for blood result delays following cyber attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The National Health Laboratory Service (NHLS) has said that while all its laboratories are operational following a cyber-attack, the issuing of test results to clinicians remains an issue.</p>
<p>“Under normal circumstances, the laboratory reports are automatically generated and sent to clinicians or made available on WebView, this incident has disabled that functionality. However, all urgent results are communicated telephonically to requesting clinicians,” the NHLS said in a statement on Wednesday</p>
<p>The NHLS announced late last month that it was hit by a cyber-attack, which compromised its systems and infrastructure.</p>
<p>In the meantime, the State-owned diagnostic pathology service provider said it was still implementing alternative plans and steps to maintain business continuity.</p>
<p>The NHLS has since distributed a critical test list to all health facilities.</p>
<p>“This is done to limit the volume of test requests, allowing laboratories to cope with the workload. However, this does not imply that routine tests will not be performed.”</p>
<p>In addition, the service provider had to come up with ways of making tuberculosis (TB) and HIV viral load historical test results available to clinicians.</p>
<p>“More tests, prioritising those on the critical test list, will be made available. In addition, we are in the process of developing an electronic registration system for registering new samples and providing test results electronically. Access to laboratory results will be the same as the historical TB and HIV viral test results.”</p>
<p>According to the NHLS, its current focus is to bring all its systems back online by the estimated mid-July to ensure end-user access remains.</p>
<p>“The NHLS is handling this challenge with extreme urgency to ensure the timely and secure recovery of all affected operations.”</p>
<p>Meanwhile, the organisation has since opened a case with the South African Police Service (SAPS) and informed all the relevant regulatory bodies about the breach.</p>
<p>“The NHLS views this attack in a serious light with significant worry and is treating the situation with great urgency. The breach has endangered the safety and well-being of millions of public health patients.”</p>
<p>The Board and its leadership team have apologised for the inconvenience caused by this occurrence and assured the public that the organisation is taking all necessary steps to resolve the situation.</p>
<p>“Despite the incident, the NHLS remains fully committed to providing high-quality diagnostic services to the public. The NHLS appreciates all stakeholders’ patience and the support we continue to receive during this difficult time.”</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/nhls-apologises-for-blood-result-delays-following-cyber-attack/">NHLS apologises for blood result delays following cyber attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>National Health Laboratory Service hit by cyber attack</title>
		<link>https://www.protectionweb.co.za/cyber-security/national-health-laboratory-service-hit-by-cyber-attack/</link>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Thu, 27 Jun 2024 09:42:55 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[ational Health Laboratory Service]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[NHLS]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=95041</guid>

					<description><![CDATA[<p>The National Health Laboratory Service (NHLS) has confirmed that it experienced an information technology (IT) security breach this past Saturday &#8211; due to a cyber attack &#8211; compromising its systems and infrastructure. A finding from the NHLS preliminary investigation, however, suggests that no patient data has been lost or compromised. “All patient data is safe. [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/national-health-laboratory-service-hit-by-cyber-attack/">National Health Laboratory Service hit by cyber attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>
<div></div>
</div>
<div class="content grid grid-cols-1 lg:grid-cols-3 gap-12 px-0 md:px-0">
<div class="col-span-1 lg:col-span-2">
<div>
<div id="block-tailwindcss-content">
<article class="node node-detail node--type-news-story-template node--view-mode-full clearfix" role="article">
<div class="node-content">
<div>
<p>The National Health Laboratory Service (NHLS) has confirmed that it experienced an information technology (IT) security breach this past Saturday &#8211; due to a cyber attack &#8211; compromising its systems and infrastructure.</p>
<p>A finding from the NHLS preliminary investigation, however, suggests that no patient data has been lost or compromised.</p>
<p>“All patient data is safe. The investigation indicated that a ransomware virus was utilised to target selected points in the NHLS IT systems, rendering them inaccessible and blocking communication from the laboratory information system and other databases to and from users,” the NHLS said.</p>
<p>The organisation’s systems remain inaccessible both internally and externally, including to and from healthcare facilities until the integrity of the environment is secured and repaired.</p>
<p>“All users will be aware that the NHLS networked laboratory system is heavily reliant on these information technology systems that have been disrupted.</p>
<p>“It has been established that sections of our system have been deleted, including in our backup server and this will require rebuilding the affected parts. Unfortunately, this will take time and investigations thus far have not advanced enough for us to give a timeframe toward the restoration of our systems and full service,” the NHLS said.</p>
<p>Stakeholders and the public will be informed as soon as more information becomes available.</p>
<p>“The cyber attacks did continue but we have been able to block these because of the additional layer of security that was built to prevent further damage. We also have had to shut down systems to enable us to repair the damage.”</p>
<p>In response to the breach, the NHLS said it swiftly activated its incident response team, which included both internal experts and external cybersecurity professionals.</p>
<p>“It must be emphasised that the NHLS’ responsibility is to ensure business continuity and quality service delivery.</p>
<p>However, the institute stated that all of its laboratories are currently fully functional and are receiving and processing clinical samples.</p>
<p>Under normal circumstances, the laboratory reports are automatically generated and sent to clinicians or made available on web view, but the incident has disabled that functionality.</p>
<p>“However, all urgent results are communicated telephonically to requesting clinicians.”</p>
<p>The organisation has acknowledged the inconvenience that this disruption may have caused, for which they apologised.</p>
<p>“The NHLS Board under the leadership of Professor Eric Buch and the executive leadership team, led by the CEO, Professor Koleka Mlisana, are working around the clock to address this unfortunate incident and ensure the continuity of our services.”</p>
<p>The NHLS is a government diagnostic pathology service responsible for supporting health departments.</p>
</div>
</div>
</article>
</div>
</div>
</div>
</div>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/national-health-laboratory-service-hit-by-cyber-attack/">National Health Laboratory Service hit by cyber attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
