South African Airways says cyberattack disrupted website, app and internal systems

Organization
South African Airways
Exploit
Hacking
Industry
Aviation

South African Airways disclosed in early May 2025 that a cyberattack had disrupted part of its technology estate. The state-owned carrier said the incident began on Saturday 3 May and temporarily cut access to its public website, its mobile application and several internal systems.

The airline said its IT team contained the intrusion and restored the affected platforms the same day. Flight operations continued to run throughout, including scheduling, distribution, reservations, online and airport check-in, baggage tracking and the Voyager loyalty programme, and contact centres and sales offices stayed open, according to statements the airline gave ITWeb and The Record.

SAA reported the matter to the State Security Agency and to the South African Police Service, which opened a criminal investigation, and notified the Information Regulator under the Protection of Personal Information Act. The airline's infrastructure is classified as a National Key Point, which drew the security agency into the response.

Chief executive John Lamola said independent digital forensic investigators had been engaged to establish the root cause and to determine whether any personal data had been taken. SAA said it had found no evidence at that stage that customer data or financial management systems were compromised, and undertook to notify individuals if that changed. No group claimed responsibility, and the airline did not say whether ransomware was involved.

Sources