Sibanye-Stillwater cyberattack hit the mining group's IT systems worldwide

Organization
Sibanye-Stillwater
Exploit
Hacking
Industry
Mining

Sibanye-Stillwater, the Johannesburg-listed precious metals producer, disclosed on July 11, 2024 that a cyberattack had affected its information technology systems globally. The company said it detected the intrusion and activated its incident response plan immediately, isolating IT systems and moving to safeguard data.

The group, which mines and processes gold, platinum group metals and other commodities across five continents, said the attack caused limited disruption to its operations worldwide and that core mining and processing continued. Teiss reported that automated systems at the company's Columbus smelter in Montana were affected and that operations there were beginning to resume at the time of publication.

Spokesman James Wellsted said the company was restoring systems gradually so that it could understand what had happened, and that it did not know who was behind the attack. Miningmx reported that there was no evidence of ransomware at that point in the investigation, and no group had publicly claimed responsibility as of mid-July 2024.

Sibanye-Stillwater said it reported the incident voluntarily to the appropriate regulators, engaged external specialists and was working toward full remediation of the effects of the attack. The company said it would provide further updates as the investigation progressed. As of mid-July 2024 it had not disclosed any theft of data. The RansomHouse group claimed the attack in late July 2024 and alleged it had taken 1.2 terabytes of data, which it leaked in mid-August. Sibanye-Stillwater confirmed a data breach in August 2024, and its Stillwater Mining unit began notifying 7,258 affected employees on September 7, 2024.

Sources