Land and Agricultural Development Bank of South Africa
Incident posture
Linked entities
- Victim
- Land and Agricultural Development Bank of South Africa
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Land and Agricultural Development Bank of South Africa faced a ransomware attack in which attackers demanded $3.1 million for decryption; the institution declined to pay and eventually recovered its systems after an extended outage. The perpetrators were not identified, and the incident was among numerous ransomware events affecting government organizations noted in a recent analysis.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In January 2026, the Land and Agricultural Development Bank of South Africa experienced a cyber‑attack that was identified as a ransomware incident. The attackers demanded a ransom of $3.1 million for the decryption key. The bank’s leadership refused to pay the demanded amount. Following the refusal, the bank’s systems were not restored until April 2026.
This incident was included in the analysis conducted by Comparitech, which tracked ransomware attacks on government entities between January and June 2026. During that six‑month window, 187 such attacks were recorded across 182 days, yielding an average of roughly one successful ransomware event per day. The study reported that just over half of the incidents were publicly confirmed by the victim organizations. The bank’s case contributed to the overall count of attacks targeting government‑linked institutions.
The Comparitech research noted that the mean ransom demand for government targets in the period was $100 000, making the $3.1 million demand an extreme outlier. The attack on the bank was carried out by an unknown assailant and was not attributed to any of the ransomware groups that were active in the same timeframe. In contrast, the most frequently identified groups were The Gentlemen, Qilin and LockBit, which together accounted for a significant share of the other incidents. No public attribution linked the bank’s breach to those or any other named threat actor.
Because the bank declined to pay the ransom, it pursued recovery without engaging in negotiation with the attackers. The restoration of systems in April marked the end of the disruption caused by the attack. The episode highlighted the variability of ransom demands and the differing outcomes when victims choose not to comply with extortion attempts. The bank’s experience remains one of the notable examples from the first half of 2026 in the broader trend of increasing ransomware pressure on government‑related organizations.
Sources
Sources available to members: 1 source.