What South Africa’s Biggest Breaches Have in Common
South Africa is not a peripheral target. It’s one of the most breached countries on the continent, and 2026 has already delivered a run of incidents at some of the country’s most trusted institutions. Look closely at how each of these attacks actually unfolded, and a pattern emerges: the technology that failed wasn’t missing. It just wasn’t watching early enough, or wasn’t set up to notice the attacker before the damage was done. That’s exactly the gap Advanced Security Technologies (AST) was built to close. Here’s what happened in four of South Africa’s most significant recent breaches, and where AST’s product suite (NanoFirewall, CATIS, ASPEN, and Baithive) would have changed the story.
Standard Bank: three weeks, unnoticed
A threat actor using the handle “Rootboy” reportedly had access to Standard Bank‘s systems for about three weeks, walking away with roughly 1.2 terabytes of data and more than 154 million database rows pulled from internal administrative and document-filing systems. The bank’s core transactional systems weren’t touched, but three weeks is a long time for an intruder to sit inside a network undetected. This is the exact scenario NanoFirewall and CATIS are designed to prevent. NanoFirewall is a self-defending engine that adapts in real time and responds to abnormal behaviour as it happens, rather than waiting for a signature match. CATIS builds a personalised threat profile from real attacker behaviour, which means the kind of slow, exploratory movement an intruder makes in week one, before they know what they’ve found, is the thing it’s built to flag. A three-week dwell time is a detection failure, and detection is the whole premise of AST’s approach.
Liberty: third-party access to client data
Standard Bank’s insurance arm, Liberty, suffered unauthorised third-party access to client data systems around the same time. Names, surnames, and ID numbers were exposed, with attackers threatening to leak further material on the dark web. Baithive is built for precisely this shape of attack. Its realistic, self-adapting cyber-clones are designed to lure an intruder away from real infrastructure and into a monitored decoy, generating threat intelligence before the attacker ever reaches genuine client data. In an incident like Liberty’s, that’s the difference between an attacker probing a fake system and an attacker walking out with real ID numbers.
Stats SA: ransomware and a ransom demand
Stats SA confirmed that a group calling itself XP95 had taken 154GB of government data and demanded a R1.7 million ransom, the same group previously linked to an attack on the Gauteng Provincial Government. Ransomware operations like this typically rely on time: time to move laterally, time to locate and stage valuable data, time to encrypt or exfiltrate before anyone notices. This is where ASPEN and NanoFirewall work together. ASPEN is a next-generation SIEM built for large-scale environments, correlating activity across a network so the early signs of staged exfiltration don’t get lost in noise, which matters enormously in a sprawling government IT estate. NanoFirewall’s autonomous response is designed to act on that signal immediately, rather than waiting for a human analyst to review an alert queue. Against a repeat offender like XP95, the goal isn’t just detecting the second attack. It’s recognising the pattern from the first one.
CIPC: “attempted” doesn’t mean contained
The Companies and Intellectual Property Commission described its breach as “attempted,” yet data was still exfiltrated, a reminder that a failed-sounding label doesn’t mean nothing got out. Attackers frequently get further than an organisation’s public statement suggests. This is a deception problem as much as a defence problem. Baithive’s role is to make it hard for an attacker to tell real infrastructure from a decoy in the first place, so that even a partially successful intrusion spends its time somewhere harmless. Paired with CATIS’s behavioural monitoring, an “attempted” breach is far more likely to stay attempted.
The common thread
None of these organisations lacked cybersecurity spend. What they lacked was visibility into attacker behaviour early enough to act. Each breach moved through a similar arc: initial access, quiet reconnaissance, lateral movement, and then exfiltration or ransom. The common thread is not the tools the victims owned, but the speed at which they could separate normal activity from attacker activity. That is the exact problem AST’s product suite is built around. NanoFirewall closes the gap between detection and response, CATIS learns the behaviour of real attackers, ASPEN correlates signals across large estates, and Baithive buys defenders time by diverting intruders into decoy environments. Together they shift the posture from waiting for alerts to making intrusions expensive and visible from the start. That’s the same gap AST’s zero-day track record speaks to directly: AST’s team has previously identified real-world exploitation of major vulnerabilities (including a SharePoint zero-day and an Oracle zero-day) weeks before those flaws were even publicly disclosed. That’s the standard South African organisations should be measuring themselves against not “did we have a firewall,” but “would we have seen this in week one, not week three.” For any organisation reading these breach reports and recognising their own risk profile, that’s the conversation worth having.




