The Passenger Rail Agency of South Africa (PRASA), a state-owned enterprise responsible for most passenger rail services in the country, has recovered over half of the 30.6 million rand (US$1.6 million) stolen in a cyberattack last year, according to its annual report.
The agency fell victim to a phishing scam, where criminals gained unauthorized access to funds through fraudulent emails. While details of the attack remain undisclosed, security experts believe insider involvement might have played a role.
PRASA confirmed recovering 15.7 million rands but offered no timeline for retrieving the remaining balance. The South African Police Service continues its investigation. "We experienced a phishing attack, resulting in a loss of 30.5 million rand," the agency stated in its report. "We recovered a significant portion and are working to reclaim the rest."
James McQuiggan, security awareness advocate at KnowBe4, suspects the attack involved creating fake employee accounts to embezzle funds. He emphasizes the importance of addressing insider threats, citing their diverse and damaging potential. "Insider threats can involve theft, sabotage, and cyberattacks," McQuiggan warns. "Organizations must implement measures to identify and mitigate these risks."
Phishing scams are a growing concern in South Africa. A study by Aon found that 22% of companies reported email interception fraud in the past five years. Additionally, digital banking fraud cases have increased by 30% since 2022, according to SABRIC.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543