CSIDB logo
Incident

Sibanye-Stillwater

Incident posture

Attack window
Jul 2024
Location
South Africa
Status
Historical
CIA posture
Available to members
Updated
2025-12-29 17:56

Linked entities

Victim
Sibanye-Stillwater
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted Sibanye-Stillwater's global IT infrastructure, causing limited operational disruptions while its core mining and processing activities remained unaffected. The company proactively isolated systems to safeguard data, engaging external experts to investigate the breach and restore services. No ransom demands were reported, and the attackers' identity remained unidentified at the time of reporting. Operations impacted included server outages and intermittent system functionality across international locations, though mining projects in South Africa, the U.S., and other countries continued normal activities during remediation efforts.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

8 techniques

Description

A cyberattack impacted Sibanye-Stillwater's global IT infrastructure starting on the morning of July 8, 2024, disrupting servers and systems across the company's operations. The Johannesburg-based precious metals producer detected unauthorized access to its IT environment, prompting immediate containment measures. Company personnel proactively isolated affected IT systems to prevent further compromise and protect sensitive data from exfiltration. This isolation caused limited operational disruptions globally, though core mining, processing, and metals production activities continued normal operations without interruption. Sibanye-Stillwater's physical mining assets in South Africa (platinum and gold), the United States (Montana palladium mine), and battery metal projects in Finland, France, and Australia remained unaffected by the digital intrusion. External cybersecurity experts were engaged to assist internal teams in forensic analysis, system restoration, and breach investigation.

Technical recovery efforts focused on identifying the intrusion vector and restoring full system functionality, with partial IT capabilities remaining operational during remediation. Company spokesperson James Wellsted confirmed no ransom demands had been received as of July 11, and threat actor attribution remained undetermined. The incident investigation prioritized understanding the attack methodology and scope while maintaining business continuity across mining operations. Sibanye-Stillwater allocated resources toward complete system remediation without disclosing specific technical details about compromised systems or data exposure risks. Corporate communications emphasized ongoing coordination between internal security teams and external consultants to resolve residual impacts from the infrastructure disruption.

Sources

Sources available to members: 1 source.

CSIDB