Cyberattack on Transnet disrupts South African container terminals

Cyberattack on Transnet disrupts South African container terminals. The disruption ran from 2021-07-22 (22 July 2021) to 2021-08-02 (2 August 2021), 12 days, affecting Durban, Cape Town, Ngqura, Port Elizabeth. Durban averaged 1.0 calls per day during the event window against an expected 1.9 (-0.9). Port Elizabeth averaged 0.3 calls per day during the event window against an expected 0.3 (+0.1). Ngqura averaged 0.5 calls per day during the event window against an expected 0.9 (-0.4). Cape Town averaged 1.1 calls per day during the event window against an expected 1.1 (0.0).

Key facts

Started
2021-07-22 (22 July 2021)
Ended
2021-08-02 (2 August 2021)
Status
ended
Severity
2 Moderate
Scope
regional
Chokepoints
None
Lanes
None
Countries
South Africa
Confidence
medium: The dates of the attack, the force majeure and its uplift are consistent across four outlets quoting Transnet Port Terminals, but Transnet's own statements from 2021 are no longer available on its site and could not be cited directly.
First reported
2021-07-27 (27 July 2021)
  • Severity basis: Container handling at four ports ran on manual systems for more than 72 hours, with force majeure in place from 2021-07-26 until it was uplifted with effect from 2021-08-02.

What happened

A cyberattack on the South African state logistics company Transnet from 2021-07-22 (22 July 2021) disrupted the systems that run its container terminals. Transnet Port Terminals declared force majeure on 2021-07-26 at the container terminals in Durban, Cape Town, Ngqura and Port Elizabeth, where loading and discharge switched to manual processes and ran more slowly than normal. Transnet Port Terminals described the incident as "an act of cyber-attack, security intrusion and sabotage". The terminal operating system was restored in stages, and Transnet said the force majeure would be uplifted with effect from 2021-08-02 once it could meet its contractual obligations again. Transnet did not name an attacker. A cybersecurity firm reported that a ransom note left on Transnet systems matched a known ransomware family.

Measured effect

Container ship port calls, Durban

Baseline (expected)
1.9 calls per day
Observed
1.0 calls per day
Change
-0.9 (percent omitted, baseline too small)
Standardised score
-0.6
Event window
2021-07-22 to 2021-08-02 (12 days)
Baseline window
2021-05-20 to 2021-07-14 (56 valid days)
Method
wfm-effect-1.0
Computed
2026-09-19 (19 September 2026), data revision 1:ac663e6ec2f8

Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.

This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.

Container ship port calls, Cape Town

Baseline (expected)
1.1 calls per day
Observed
1.1 calls per day
Change
0.0 (percent omitted, baseline too small)
Standardised score
0.0
Event window
2021-07-22 to 2021-08-02 (12 days)
Baseline window
2021-05-20 to 2021-07-14 (56 valid days)
Method
wfm-effect-1.0
Computed
2026-09-19 (19 September 2026), data revision 1:445a8679a803

Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.

This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.

Container ship port calls, Ngqura

Baseline (expected)
0.9 calls per day
Observed
0.5 calls per day
Change
-0.4 (percent omitted, baseline too small)
Standardised score
-0.4
Event window
2021-07-22 to 2021-08-02 (12 days)
Baseline window
2021-05-20 to 2021-07-14 (56 valid days)
Method
wfm-effect-1.0
Computed
2026-09-19 (19 September 2026), data revision 1:7f673891853d

Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.

This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.

Container ship port calls, Port Elizabeth

Baseline (expected)
0.3 calls per day
Observed
0.3 calls per day
Change
+0.1 (percent omitted, baseline too small)
Standardised score
+0.1
Event window
2021-07-22 to 2021-08-02 (12 days)
Baseline window
2021-05-20 to 2021-07-14 (56 valid days)
Method
wfm-effect-1.0
Computed
2026-09-19 (19 September 2026), data revision 1:2abdd20258a5

Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.

This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.

Timeline

  1. Transnet systems are disrupted by a cyberattack, affecting IT applications used across the company and the terminal operating system at its container terminals. [s1] [s2]
  2. Transnet Port Terminals declares force majeure at the container terminals in Durban, Cape Town, Ngqura and Port Elizabeth, and moves container handling onto manual systems. [s1] [s2]
  3. A cybersecurity firm reports that a ransom note left on Transnet computers is linked to a ransomware family known as Death Kitty, Hello Kitty and Five Hands. Transnet does not attribute the attack. [s4]
  4. Transnet says operations have normalised after the terminal operating system was restored in stages and that the force majeure will be uplifted with effect from the following day. [s3]
  5. The force majeure declared at the four container terminals is uplifted. [s3]

Cause

Transnet Port Terminals said it had experienced "an act of cyber-attack, security intrusion and sabotage" that disrupted its normal processes. A cybersecurity firm reported that a ransom note found on Transnet systems was linked to a known ransomware family. Transnet did not publicly identify those responsible. Attributed by: Transnet Port Terminals, with the ransomware link attributed by the cybersecurity firm CrowdStrike. [s1] [s4]

Resolution

2021-08-02 (2 August 2021): Transnet restored the terminal operating system in stages across the container terminals, said operations had normalised and uplifted the force majeure with effect from 2021-08-02. [s3]

Corrections

No corrections to this record as of 2026-09-16 (16 September 2026).

Sources

  1. [s1] Moneyweb, Transnet cyber attack confirmed: Port terminals division declares force majeure, published 2021-07-27 (27 July 2021), accessed 2026-09-15. Archived copy. (press)
  2. [s2] The Maritime Executive, Second Force Majeure at South African Ports Following Cyberattack, published 2021-07-27 (27 July 2021), accessed 2026-09-15. Archived copy. (press)
  3. [s3] Daily Maverick, Transnet lifts force majeure on ports after operations normalise following cyberattack, published 2021-08-01 (1 August 2021), accessed 2026-09-15. Archived copy. (press)
  4. [s4] TechCentral, Transnet likely hit by Death Kitty ransomware attack, published 2021-07-29 (29 July 2021), accessed 2026-09-15. Archived copy. (press)