
Bulk water utility Rand Water on Thursday disclosed that it had become the latest institution to fall prey to cyberattackers. However, it said the impact on its operations has been minimal.
Rand Water’s primary activity is the provision of bulk water supply services – potable bulk water and sanitation services — in Gauteng and neighbouring provinces.
“Rand Water wishes to advise noteholders that it is currently responding to a cybersecurity incident affecting certain information technology systems,” it said in a statement.
“The incident is being actively investigated and managed with the support of relevant internal and external specialists.”
It said its “critical operational activities”, including water treatment processes, water quality control systems and bulk water supply operations, remain fully operational and continue to function normally.
“Regular water quality monitoring and testing remain in place to ensure the continued delivery of safe potable water in accordance with applicable standards,” the statement said.
It added that its treasury operations continue to operate “through its disaster recovery environment” and that it continues to meet “all of its obligations in respect of its listed debt securities”.
No missing funds
“There is currently no indication of any missing funds or impairment of Rand Water’s ability to service its debt obligations or meet its obligations to noteholders arising from the incident.”
It provided no immediate further information on the nature of the incident, including the suspected attackers or the type of attack involved
Rand Water’s disclosure came through a note to holders of its listed debt securities, a duty that flows from its presence on the JSE’s debt board. Most public sector entities carry no equivalent obligation, which is part of why the true scale of the problem is difficult to measure: incidents tend to surface through leaks, auditor findings or the attackers themselves rather than through routine reporting.
The auditor-general has already warned about the state’s exposure. Its 2026 report on government cyber defences singled out the South African Bureau of Standards, whose information systems were fully encrypted in a November 2024 ransomware attack that shut down its business applications and left it unable to submit its 2024/2025 financial statements.

The auditor-general found the bureau’s risk had been heightened by outdated systems, weak password policies, poor access controls and an untested disaster recovery plan, and that it had not acted on recommendations dating back to 2021/2022.
Transnet’s 2021 ransomware attack, which encrypted its systems and caused weeks of delays at South Africa’s ports, remains the most disruptive incident at a state-owned company to date.
The pattern is regional as well as local. Check Point’s 2025 African Perspectives on Cyber Security report found that 41% of the world’s major ransomware attacks target African organisations, despite the continent’s comparatively thin digital infrastructure. Rand Water has not said whether ransomware was involved in its own incident. – © 2026 NewsCentral Media
- Subscribe to TechCentral’s daily newsletter
- Get breaking news alerts on WhatsApp


