Transnet ransomware, July 2021: the week South Africa's ports went manual

On 22 July 2021, Transnet — South Africa's state-owned operator of ports, freight rail and pipelines — announced it was experiencing a disruption to its IT systems. Within days it became clear that this was one of the most consequential cyberattacks ever to hit African critical infrastructure: container terminal operations were knocked offline, and the company took the extraordinary step of declaring force majeure.

What happened

Transnet detected what it initially described as "an act of cyberattack, security intrusion and sabotage" and shut down affected IT systems as a containment measure. The Navis container terminal operating system used at its ports was among the systems taken offline, forcing terminals at Durban, Cape Town, Gqeberha (Port Elizabeth) and Ngqura to fall back on manual, paper-based processing.

On 26 July 2021, Transnet Port Terminals declared force majeure at its container terminals — a formal notice to customers that it could not meet contractual obligations due to events beyond its control. The Port of Durban alone handles a majority of South Africa's container traffic and serves as a gateway for several landlocked neighbouring economies, so the disruption rippled well beyond one company. Transnet restored operations progressively and lifted the force majeure on 2 August 2021.

How the attack worked

Transnet has never publicly confirmed the initial intrusion vector. Media reporting at the time — notably by Bloomberg, whose journalists reviewed a ransom note left on Transnet computers — linked the incident to ransomware associated with the "Death Kitty" (also known as HelloKitty) family. Transnet itself was measured in its public statements and did not confirm attribution.

What can be said with confidence is that ransomware operations of this kind typically begin with a human or credential failure: a phishing email, stolen or reused credentials, or an exposed remote-access service. Because the entry point at Transnet was never disclosed, no one outside the investigation can say which of these applied here. The broader lesson stands regardless: enterprise ransomware almost always crosses a human threshold before it ever touches an operational system.

The impact

The attack disrupted container handling for roughly a week during South Africa's citrus export season, when time-sensitive perishable cargo was moving through the ports at peak volume. Shipping lines rerouted or delayed vessels, truckers queued at terminals processing paperwork by hand, and exporters warned of losses. The incident also arrived days after severe civil unrest in KwaZulu-Natal had already strained supply chains — a compounding shock that underlined how little slack existed in the system.

Beyond the immediate operational cost, the attack was widely described by analysts, including the Institute for Security Studies, as a wake-up call: the first time a cyberattack had so visibly interrupted the functioning of African critical trade infrastructure.

Lessons for African organisations

  • Assume the human layer is the front door. Whatever the vector was at Transnet, most ransomware campaigns start with phishing or compromised credentials. Continuous, measured awareness training is a critical-infrastructure control, not an HR formality.
  • Segment IT from operational systems. The ability to isolate terminal operating systems limited the damage; tighter segmentation limits it further and can keep cargo moving while IT recovers.
  • Rehearse manual fallback before you need it. Transnet's terminals kept working on paper. That capability only exists if it is planned, documented and practised.
  • Plan the legal and customer response in advance. Declaring force majeure is a significant commercial act; knowing when and how to communicate it is part of incident readiness.
  • Measure recovery, not just prevention. A week to restore operations is the metric customers remember. Recovery objectives deserve the same scrutiny as firewalls.

Sources

  • Transnet SOC statements and force majeure notice, July–August 2021
  • Reuters coverage of the attack and restoration of operations, 2021
  • Bloomberg reporting on the ransom note and suspected ransomware family, 2021
  • Institute for Security Studies (ISS) analysis of the incident, 2021

If a single email can idle a port, it is worth knowing how your own organisation would hold up — our free Human Risk Maturity Assessment takes four minutes and shows you where you stand.