[Image: Rand Water / Facebook]
Rand Water has confirmed a cybersecurity incident affecting some of its IT systems.
The disclosure was made to holders of Rand Water’s listed debt securities on 3 September, after TechCentral reported that South Africa’s biggest water utility had become the latest public-sector institution hit by cyberattackers.
Rand Water’s message to the market was careful, indicating the incident is “affecting certain information technology systems”, and is being investigated and managed with internal and external specialists.
Rand Water said its critical operational activities remain fully operational, including water treatment processes, water quality control systems and bulk water supply operations.
In a separate customer-facing assurance carried by Infrastructure News, Rand Water said the “quality and supply of water have not been affected” and that its testing continues under SANS 241, South Africa’s drinking-water standard.
Rand Water is not a small back-office agency with a forgotten server under someone’s desk. It is established under the Water Services Act, with the South African government as its sole shareholder through the Department of Water and Sanitation, and its core job is bulk potable water and sanitation services in its service area.
As South Africa’s biggest water utility, it supplies Gauteng and neighbouring provinces. In other words, this is the infrastructure layer you only want to think about when it works.
Rand Water also told noteholders that treasury operations are continuing through its disaster recovery environment, and that it continues to meet all obligations linked to its listed debt securities.
“There is currently no indication of any missing funds or impairment of Rand Water’s ability to service its debt obligations or meet its obligations to noteholders arising from the incident,” the utility said in the SENS notice.
Rand Water has not named a suspected attacker, described the type of attack, said whether any data was accessed, or given a timeline for restoring full system functionality.
That does not mean the tap water is unsafe. It does mean the public still does not know much about what happened inside the IT environment of one of the country’s most important water entities.
TechCentral points out that the disclosure came because Rand Water has listed debt securities on the JSE’s debt board, which creates a market-reporting duty that many other public-sector entities do not have in the same way.
South Africa has seen this movie before, and the sequel is never cheaper. Transnet’s 2021 ransomware attack snarled port operations for weeks, while the auditor-general has already warned about weak cyber defences across parts of the state, including the South African Bureau of Standards ransomware attack in November 2024.
Rand Water says it will keep monitoring the situation and provide further market updates if any material developments arise.
For now, the taps are still running.
[Sources: TechCentral, SENS via Sharenet & Infrastructure News]
