CSIDB logo
Incident

Land and Agricultural Development Bank of South Africa

Incident posture

Attack window
Jan 2026
Location
South Africa
Status
Resolved
CIA posture
Available to members
Updated
2026-09-03 17:44

Linked entities

Victim
Land and Agricultural Development Bank of South Africa
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Undetermined
Disclosed
Jul 2026
Resolved
Apr 2026

Summary

Land and Agricultural Development Bank of South Africa faced a ransomware attack in which attackers demanded $3.1 million for decryption; the institution declined to pay and eventually recovered its systems after an extended outage. The perpetrators were not identified, and the incident was among numerous ransomware events affecting government organizations noted in a recent analysis.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In January 2026, the Land and Agricultural Development Bank of South Africa experienced a cyber‑attack that was identified as a ransomware incident. The attackers demanded a ransom of $3.1 million for the decryption key. The bank’s leadership refused to pay the demanded amount. Following the refusal, the bank’s systems were not restored until April 2026.

This incident was included in the analysis conducted by Comparitech, which tracked ransomware attacks on government entities between January and June 2026. During that six‑month window, 187 such attacks were recorded across 182 days, yielding an average of roughly one successful ransomware event per day. The study reported that just over half of the incidents were publicly confirmed by the victim organizations. The bank’s case contributed to the overall count of attacks targeting government‑linked institutions.

The Comparitech research noted that the mean ransom demand for government targets in the period was $100 000, making the $3.1 million demand an extreme outlier. The attack on the bank was carried out by an unknown assailant and was not attributed to any of the ransomware groups that were active in the same timeframe. In contrast, the most frequently identified groups were The Gentlemen, Qilin and LockBit, which together accounted for a significant share of the other incidents. No public attribution linked the bank’s breach to those or any other named threat actor.

Because the bank declined to pay the ransom, it pursued recovery without engaging in negotiation with the attackers. The restoration of systems in April marked the end of the disruption caused by the attack. The episode highlighted the variability of ransom demands and the differing outcomes when victims choose not to comply with extortion attempts. The bank’s experience remains one of the notable examples from the first half of 2026 in the broader trend of increasing ransomware pressure on government‑related organizations.

Sources

Sources available to members: 1 source.

CSIDB