CSIDB logo
Incident

South African Weather Service

Incident posture

Attack window
Jan 2025
Location
South Africa
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 00:16

Linked entities

Victim
South African Weather Service
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The South African Weather Service experienced a cyber attack that disabled its ICT systems, affecting aviation and marine services, email and website access. In response, the organization activated alternative communication channels, using social media to provide weather updates and maintaining essential meteorological products through other means. Some media outlets reported missing daily forecasts, while several stakeholders requested briefings on the incident’s impact and remediation efforts. The CEO noted that recovery would take time, with external cybersecurity experts and internal technicians working on‑site to remove the malicious code, restore data from backups and gradually reopen the network. The organization has also reported the criminal activity to the relevant authorities and advised the public to rely on its social platforms for weather information.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Saturday, 25 January 2025, an attempted cyber intrusion against the South African Weather Service was detected but did not succeed in compromising systems.
The following evening, Sunday, 26 January 2025, a criminal security breach succeeded, causing the SAWS ICT systems to go down.
As stated in the service’s own update, “The SAWS ICT systems went down on Sunday evening, 26 January due to a criminal security breach. Our aviation and marine services were affected as well as emails and website, however, alternative communication measures were put in place.”
The notice also noted that “The public is advised to rely in our social Media platforms for weather information” and that “The SAWS is in the process of reporting the criminal act to relevant authorities.”
The update further clarified that “The attack was the second in the space of two days after the first attempt on Saturday 25 Januarie failed.”

Two weeks after the incident, on 10 February 2025, SAWS reported that its ICT systems remained in unscheduled downtime as a result of the data breach.
The organisation explained, “The SAWS’ ICT systems, which are the bedrock of the entity’s weather, climate and administrative operations, remain in an unscheduled downtime following a data breach the organisation suffered two weeks ago.”
Despite the outage, SAWS continued to provide essential meteorological services such as aviation, marine and severe weather products using alternative methods.
The service advised the public to obtain weather updates through its social media channels during the disruption.
SAWS had reached out to most stakeholders, partners and clients to inform them of the impact of the breach on the delivery of services.

Some media houses issued complaints that they had not been receiving daily weather forecasts, while other stakeholders approached SAWS to request briefings on the extent of the problem and what was being done to address it.
CEO Ishaam Abader acknowledged that restoration would take time, but confirmed that a team of cybersecurity experts was on‑site.
He stated, “The expert team of external cybersecurity specialists and our own ICT technicians remain on site to flush out the virus used by the cyber criminals to encrypt our systems, and to recover our data from the backups before beginning to reopen our network.”
The ongoing work involved removing the malicious code, restoring data from backups, and gradually reopening the network to resume normal operations.
Throughout the incident, SAWS maintained communication with the public and partners while working to restore its critical ICT infrastructure.

Sources

Sources available to members: 2 sources.

CSIDB