Latest News

GEPF is 110.1% funded

Government Pensions Administration Agency (GPAA) data breach

2 min read

MEDIA RELEASE

12 March 2024

The Government Employees Pension Fund (GEPF) has noted the release of data purportedly from its administrator, the Government Pensions Administration Agency (GPAA) by the ransomware group LockBit.

The GEPF is extremely concerned with this alleged security breach, as it was informed by GPAA that no data breach had occurred when it was notified of an attempt to gain access to GPAA systems by unknown individuals on the 16 February 2024. The GPAA subsequently established that this was an attempt by the ransomware group LockBit.

This morning, 12 March 2024, following the release of certain GPAA data by LockBit on 11 March 2024, the GEPF has been informed by GPAA that preliminary investigations has found that the certain GPAA systems were compromised. The GPAA is investigating the alleged data breach and whether this impacts the GEPF.

GPAA has reconfirmed that preventative action was taken when it became aware of the attempted access to its systems which included “shutting down” all systems to isolate affected areas. GPAA further confirmed that pension payments are not affected.

The GEPF is engaging with the GPAA and its oversight authority, the National Treasury to establish the veracity and impact of the reported data breach and will provide a further update in due course. Until the facts have been adequately established, the GEPF is unable to comment further on the matter.

Issued by:

Government Employees Pension Fund
For more information, please contact:

Matau Molapo
Email: matau.molapo@gepf.co.za
012 424 7315

Like what you see? Share with a friend.

Founder of SAAS First – the Best AI and Data-Driven Customer Engagement Tool


With 11 years in SaaS, I’ve built Million Verifier and SAAS First. Passionate about SaaS, data, and AI.

Share with your community!

In this article

Related Articles

Media Statement Pretoria:  02 May 2024 The Government Employees Pension Fund (GEPF)

Media Release09 May 2024, Pretoria In a significant move to bolster support

MEDIA RELEASE 12 March 2024 The Government Employees Pension Fund (GEPF) has

The Government Employees Pension Fund (GEPF) has become aware of fraudulent letters

The Government Employees Pension Fund (GEPF) is pleased to announce an annual

Breach Notification

NOTIFICATION OF SECURITY COMPROMISE AS PER SECTION 22 OF THE PROTECTION OF PERSONAL INFORMATION ACT, 4 OF 2013 ("POPIA")

The GEPF experienced a security breach and the compromise of personal information held on the GPAA systems and records between February and March 2024. Data subjects were notified of the security breach and potential compromise of personal information on 20 March 2024.

The GPAA immediately shut down all its systems and initiated its Cyber Incident and Response Plan to mitigate the damage at the time of the security compromise. As a result, the compromise of personal information was isolated and curtailed. The GPAA initiated an investigation into the cause and extent of the security breach and committed to providing updates/outcomes of the investigation as soon as practically possible.

Although the investigation is still ongoing, the assessment recently revealed a compromise of personal information of a number of data subjects. The extent of the compromise of personal information is still being investigated and will be communicated on the conclusion of the investigation.

The GPAA has put various additional control measures in place to strengthen the security safeguards on its systems since the incident. The GPAA is working with security agencies to strengthen control measures and avoid future reoccurrences.

The GEPF and GPAA recognises the importance of safeguarding personal information and is working actively to prevent any recurrence of security compromises on the GEPF and GPAA systems.

We apologise for any inconvenience caused and assure you that every reasonable step has been taken to ensure that all GPAA systems and platforms are safe and protected from unauthorised and unlawful access.

The security compromise was reported to the relevant authorities, entities and regulators for further investigations, support and transparency.

Gepf Logo