City of Johannesburg, October 2019: when a metro took itself offline
Late on 24 October 2019, South Africa's largest city announced that it had detected a breach of its network. Within hours, the City of Johannesburg had shut down its website, e-services and billing systems as a precaution — a deliberate self-imposed blackout that left millions of residents unable to transact with their municipality while investigators worked.
What happened
A group calling itself the "Shadow Kill Hackers" claimed responsibility for the intrusion and demanded a ransom of 4 bitcoins, threatening to upload stolen city data to the internet if payment was not made by a stated deadline. The attackers claimed to have obtained passwords and sensitive information; the full extent of what, if anything, was actually taken was not publicly confirmed by the city.
The City of Johannesburg responded by taking key systems offline, including the municipal website, e-services portal and billing platforms, and publicly stated that it would not pay the ransom. Services were restored progressively over the following days. Notably, this was the second cyber incident to touch the city that year: in July 2019, City Power, the municipal electricity utility, had been hit by a separate ransomware attack that disrupted its prepaid electricity vending systems.
How the attack worked
The city did not publicly disclose how the attackers gained access to its network, and no confirmed technical account of the intrusion vector was published. This is itself a common pattern in public-sector incidents: attribution and vector details often stay inside the investigation.
What the incident clearly was, however, was an extortion operation aimed at a data-rich, service-critical target. Municipalities hold identity data, billing records and payment details for entire populations, and they depend on large workforces with broad system access — exactly the conditions under which a single phished credential or reused password can open the door. Whether or not that was the case here, the attackers' claim to hold "all passwords" was calibrated to exploit precisely that fear.
The impact
For several days, residents could not use the city's online billing, e-services or customer portals, and some internal systems were unavailable to staff. Call centres and walk-in centres absorbed the load. The city extended payment deadlines for residents affected by the outage. The direct financial cost was not published, but the episode demonstrated how a cyber incident against a metro translates immediately into a citizen-service crisis — and how the decision to take systems offline, though prudent, carries its own heavy operational price.
The incident also placed South African public institutions on notice. Coming three months after the City Power attack, it showed that local government had become a deliberate, repeat target for financially motivated actors.
Lessons for African organisations
- Refusing to pay requires preparation. Johannesburg could decline the ransom because it was able to restore services from its own systems. That position must be earned in advance with tested backups and recovery plans.
- Public-sector staff are prime phishing targets. Large, distributed workforces with access to citizen data need continuous awareness training and simple, well-known channels to report suspicious emails.
- Plan the citizen-facing fallback. When digital channels go down, call centres and physical offices become the continuity plan. Capacity and scripts for that scenario should exist before the incident.
- Treat the first incident as a rehearsal for the second. The July City Power attack preceded the October breach by three months. Every incident should harden the institution, not just be survived.
- Communicate early and plainly. The city's rapid public statements, including its refusal to pay, helped it keep control of the narrative during the outage.
Sources
- City of Johannesburg public statements and service updates, October 2019
- Reuters and BBC coverage of the breach and ransom demand, 2019
- Reporting on the July 2019 City Power ransomware incident, 2019
- ITWeb and local South African media coverage, 2019
Municipal resilience starts with knowing where the human gaps are — the free Human Risk Maturity Assessment gives any organisation a four-minute baseline.