Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Stats SA

Stats SA Vendor Cyber Rating & Cyber Score

statssa.com.au

Stats SA is a multi-disciplinary and progressive practice offering accounting, taxation and business advisory services across a diverse range of industries and professions


Stats SA A.I CyberSecurity Scoring

Stats SA
Company Information
Website:https://www.statssa.com.au/
Employees number:234
Number of followers:300
NAICS:5412
Industry Type:Accounting
Homepage:statssa.com.au
Stats SA Risk Score (AI oriented)
Between 600 and 649
logo
Stats SAAccounting
Updated:
30/03/2026
604/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Stats SA Global Score (TPRM)
xxxx
logo
Stats SAAccounting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Stats SA
Stats SAPoor
Current Score
604Caa (POOR)
01000
1 incidents
-154 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
616Before Incident
JULY 2026
616Before Incident
JUNE 2026
613Before Incident
MAY 2026
610Before Incident
APRIL 2026
607Before Incident
MARCH 2026
756Before Incident
Ransomware
01 Mar 2026Stats SA
Statistics South Africa: Statistics South Africa Hit by Ransomware Attack, Hackers Claim Theft of 450,000 Files

Stats SA Hit by Ransomware Attack: Hackers Claim Theft of 450,000 Files

602After Incident
CRITICAL-154
STA1774866616
Stats SA Hit by Ransomware Attack: Hackers Claim Theft of 450,000 Files South Africa’s national statistics agency, Statistics South Africa (Stats SA), has been targeted in a ransomware attack by the cybercrime group XP95, which claims to have stolen over 450,000 files totaling 154 GB of data. The breach, confirmed by Stats SA, marks the second major government-related cyber incident in South Africa this month, raising concerns about the security of sensitive public sector data. XP95, a relatively new ransomware and extortion group first identified in March 2026, has demanded a $100,000 (R1.7 million) ransom to prevent the public release of the stolen information. The group previously breached the Gauteng Provincial Government, stealing 3.8 terabytes of personal data from millions of residents. Unlike traditional ransomware attacks that focus on encryption, XP95 employs a "double extortion" tactic, threatening to leak or sell data if payment is not made. Stats SA, responsible for critical national data including census records, economic indicators, and household surveys has not disclosed the full extent of the compromised information. Authorities are investigating whether personal details, such as names, addresses, or identification numbers, were exposed. Even anonymized data can pose risks if re-identified through cross-referencing with other sources. The attack could undermine public trust in government data collection, particularly ahead of South Africa’s next population census. A successful data leak may deter citizens from participating in future surveys, impacting the reliability of official statistics used for policy-making, budget decisions, and research. South Africa has seen a rise in cyberattacks targeting government institutions, state-owned enterprises, and healthcare providers. Public sector organizations are prime targets due to the vast amounts of personal data they hold, which can be exploited for fraud or sold on the dark web. XP95’s tactics reflect a broader trend of cybercriminals leveraging data theft alongside encryption to maximize pressure on victims. Stats SA has activated its incident response team and is collaborating with cybersecurity experts and law enforcement to contain the breach and investigate the attack vector. The agency has not indicated whether it will pay the ransom, though cybersecurity best practices advise against it, as payment does not guarantee data protection. The incident underscores the need for strengthened cybersecurity measures across South Africa’s public sector, including network segmentation, regular security audits, employee training, and robust backup systems. As the investigation continues, the focus remains on securing systems and preventing further exposure of sensitive data.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (extortion)
IMPACT
Data Compromised: 450,000 files (154 GB)Operational Impact: Potential undermining of public trust in government data collectionBrand Reputation Impact: Undermined public trust in Stats SAIdentity Theft Risk: Possible if personal details were exposed
DATA BREACH
Type Of Data Compromised: National statistics data (census records, economic indicators, household surveys)Number Of Records Exposed: 450,000 filesSensitivity Of Data: High (potential personal details, anonymized data at risk of re-identification)Data Exfiltration: Yes (154 GB stolen)Personally Identifiable Information: Possible (names, addresses, identification numbers)
FEBRUARY 2026
756Before Incident
JANUARY 2026
756Before Incident
DECEMBER 2025
756Before Incident
NOVEMBER 2025
756Before Incident
OCTOBER 2025
756Before Incident
SEPTEMBER 2025
756Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Stats SA ?
?
What was Stats SA's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Stats SA's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Stats SA's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Stats SA ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Stats SA's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?