IMG-20240925-WA0023

SA is Africa’s cybercrime epicentre

By: Thobeka Ngema

South Africa has become the continent’s epicentre for cybercriminal activity, according to Interpol’s latest African Cyberthreat Assessment Report.

While the report highlights alarming statistics, such as South Africa accounting for 92% of all ransomware detections in Africa, industry experts warn that the true crisis lies not just in the frequency of attacks, but in a systemic failure to defend against them.

“South Africa accounted for 92% of all ransomware detections in Africa by TrendAI, with incidents affecting critical infrastructure such as the South African Weather Service, South African Airways, and Namibia’s Paratus Telecom,” the report read.

It said that regarding Distributed Denial-of-Service (DDoS) attacks, South Africa alone recorded 213 523 attacks, a single incident reaching 312 Gbps – dwarfing all other regions.

Moreover, phishing was rampant, with South Africa accounting for almost 40% of all African phishing detections, followed by Mauritius at 22%, according to SOCRadar.

The report said that despite mature regulatory frameworks like South Africa’s Cybersecurity Act and Mauritius’ Digital Transformation Blueprint, the region remains vulnerable to AI-enabled threats. Trends like Zambian scam centres and South African deepfake-sextortion highlight how advanced infrastructure often coexists with systemic exploitation.

“South Africa accounted for 92% of all ransomware detections in Africa, according to TrendAI data,” the report read.

In 2025, TrendAI data indicated that 70% of Business E-mail Compromise detections originated in South Africa and 29% from Nigeria. TrendAI also recorded 600 000 sextortion detections in Africa in 2025, with the majority originating from South Africa (30%), Kenya (13%), Côte d’Ivoire (11%), Ethiopia (8%), and Angola (4%).

Additionally, the Shadowserver Foundation identified more than 6 000 exploitable vulnerabilities across Africa in 2025, with the highest concentrations in South Africa (43.6%), Kenya, and Nigeria, the same countries with the largest internet user bases.

Specialist investigator Anthony Boucher said: “South Africa is ground zero for cybercrime in Africa. 92% of ransomware attacks? That’s not a statistic – that’s a crisis. We’re the most connected country on the continent, and we’ve basically rolled out the red carpet for criminals.”

Boucher said the 43% vulnerability figure tells him the country is not even doing the basics. Unpatched systems are being exploited.

He said the AI part is most shocking. Criminals are using deepfakes and automated attacks, while South African investigators lack the skills to spot it.

“The SA Weather Service attack should have been a wake-up call. They disrupted aviation systems – not for money, but for chaos,” said Boucher, who is the Mike Bolhuis’ Specialised Security Services, Cybercrimes Division national head.

He said that while good laws exist on paper, implementation is almost non-existent.

“Our police don’t have the tools or training. Some stations don’t even have working computers. How do you investigate a digital crime without digital forensics?” Boucher asked.

He said criminals exploit the lack of 24/7 monitoring by finding targets on weekends. Furthermore, critical information silos persist: banks cannot share real-time fraud data with police without a court order, causing delays that allow funds to be siphoned off before law enforcement can act.

“And we’ve got a massive skills gap. Crypto-tracing, malware analysis, AI detection – we’re short-staffed and under-trained,” Boucher said.

“The solution is for the government to cooperate with the private sector, and for the law to allow for the sharing of protected information on a basis of urgency. Training and resources should be a priority for law enforcement; without it, South Africa will continue to be a sitting duck.”

Professor of cybersecurity at the University of Johannesburg Basie von Solms said there is nothing dramatically new in the report. Many of the things reported on have been well-known for many years, but nothing is being done about it.

Von Solms said the major problem for cybercrime is the lack of political will from the government as revealed by Auditor-General reports from the past five years which consistently show that 50–70% of audited government IT systems contain known, unfixed vulnerabilities. A primary obstacle to addressing these security failures is the persistent lack of political will to act on these findings.

“It may be that there’s no money to do it, then we shouldn’t have the systems,” Von Solms said, adding that the Auditor-General reports that South Africa is using outdated systems and in some cases, the licence has expired.

Secondly, he said there is a lack of cybersecurity awareness from the general public.

“The government, I think, has got a duty because if you look at the Interpol report, if you look at cybercrime using attack methods like phishing, sextortion, these are all attack methods which are based on the fact that the end user does not recognise it, is not aware of the risk of using cyberspace,” Von Solms said.

Article Source: https://iol.co.za/mercury/news/2026-08-06-sa-is-africas-cybercrime-epicentre/

IMG_3211

AI is raising South Africa’s cybersecurity stakes

By: Kgomotso Lebele

South African organisations are facing a growing cybersecurity challenge at a time when AI is accelerating technological change across every sector of the economy. The country was already one of the most targeted cyber environments in Africa before the latest advances in AI. According to industry research, local organisations experienced a sharp increase in cyber attacks during 2025, while cyber crime continues to impose significant financial and operational costs on businesses, government institutions and consumers.

At the same time, AI is changing how cyber threats emerge and evolve. Tasks that once required significant time, specialised skills and large teams can increasingly be performed faster and at greater scale. For organisations that already have security weaknesses, this creates additional pressure to strengthen their cyber resilience. Research into advanced AI systems has highlighted the potential to identify previously unknown software vulnerabilities across widely used operating systems and browsers, capabilities that have significant implications for both attack and defence.

As advanced AI systems become more accessible, organisations will need to prepare for a future where cyber threats can be identified, developed and executed far more quickly than before. For South African businesses, the concern is not simply the technology itself, it is whether existing security foundations are strong enough to respond to a rapidly changing threat landscape.

Accenture’s State of Cybersecurity research found that only 44% of technology leaders in South Africa acknowledge that AI is advancing faster than their organisations’ cyber security capabilities. Yet assessments conducted across organisations revealed security gaps that could become increasingly difficult to manage as AI capabilities continue to evolve.

Several areas stand out, and cloud security is one. Many digital transformation and AI initiatives rely heavily on cloud environments, yet Accenture’s research found that only 18% of South African organisations have full visibility into their cloud security configurations, while just 6% have approved security baselines in place. Without strong governance and oversight, cloud platforms can create unnecessary risk exposure.

Data governance presents a similar picture. AI systems depend on access to data, making it increasingly important for organisations to understand what information they hold, where it resides, and how it is protected. Only 18% of South African organisations have classified their data according to sensitivity, and just 24% have established clear policies governing AI use. Without these controls, it becomes harder to manage risk and apply appropriate safeguards.

Identity security is another critical area. Modern organisations must manage access across employees, contractors, third parties, applications and, increasingly, AI agents. Yet only 28% of organisations have adopted a continuous verification approach to access management, while just 8% enforce least-privilege access controls. As digital ecosystems become more complex, identity management is becoming one of the most important components of cybersecurity.

Software development practices also require attention. Only 8% of South African organisations integrate security testing throughout the software development lifecycle rather than treating it as a final step before deployment. As AI accelerates the discovery of vulnerabilities, embedding security from the outset becomes increasingly important.

South Africa has already experienced the consequences of major cyber incidents. The 2021 cyber attack on a state-owned freight company disrupted operations at key ports and affected supply chains across multiple sectors of the economy. The incident demonstrated that cybersecurity is no longer solely a technology concern; it has direct implications for business continuity, economic activity and public confidence.

As AI capabilities continue to mature, the potential impact of cyber incidents may become even more significant. Reports suggest that AI is already being used to support activities such as vulnerability discovery, reconnaissance and elements of attack planning. While human oversight remains involved, automation is increasing the speed and scale at which these activities can occur.

Building resilience

Organisations should ensure that security is considered at the beginning of digital and AI initiatives rather than after deployment. Cloud governance, data management, identity controls and application security should form part of planning and implementation processes from the start. As AI becomes more embedded across business functions, security needs to be integrated into decision making from the outset.

Businesses should also explore how AI can strengthen their own defensive capabilities. AI-powered monitoring, threat detection, and vulnerability management tools can help security teams identify risks earlier and respond more effectively. Used responsibly, these capabilities can improve visibility across increasingly complex technology environments and help organisations keep pace with a rapidly evolving threat landscape.

South African organisations have spent years investing in digital capabilities to improve customer experiences, drive innovation and support growth. Those investments will continue to create opportunities, but they also increase the importance of cyber resilience. As AI becomes more embedded in business operations, organisations that strengthen their security foundations and build resilience into their digital strategies will be better positioned to realise the benefits of AI while managing the risks that accompany it.

 

Article Source: https://www.instrumentation.co.za/27921r

 

 

IMG_3216

Six Cybersecurity Trends Shaping South Africa in 2026

By: Yesh Surjoodeen

South Africa is operating in one of the most complex cyber threat environments globally. Hybrid work is now entrenched, digital infrastructure is expanding rapidly, and organisations are more distributed than ever. At the same time, cybercriminal syndicates are becoming more coordinated, more automated and increasingly driven by artificial intelligence.

The impact is already significant. SABRIC estimates cybercrime costs South Africa around R2.2 billion annually, with phishing responsible for 78% of all digital banking fraud in 2025. Accenture reports that 54% of local breaches involved compromised user identities. These figures underscore a hard truth: traditional, perimeter-based security models are no longer sufficient.

Looking ahead to 2026, South African organizations must rethink cyber resilience across people, devices, identities and data. Based on HP’s global security research, six trends will shape the next phase of cybersecurity locally.

  • Cookie theft will overtake password theft
    As multi-factor authentication becomes standard, attackers are shifting from stealing passwords to hijacking browser cookies and session tokens bypassing MFA entirely. This poses serious risk for high-value sectors such as financial services, telecoms, retail, healthcare and government. Protecting the browser through isolation, stronger application controls, regular token rotation and tighter privilege management is now critical.
  • AI will industrialize cyber reconnaissance
    Cybercrime groups are rapidly adopting AI agents to automate reconnaissance, map environments and tailor attacks at scale. INTERPOL reported a 17% rise in AI-assisted cybercrime across Africa in 2025, with South Africa among the most affected. In this context, organizations must assume some attacks will evade detection. Resilience will depend on containment-first strategies, including device isolation, automated rollback and rapid fleet recovery.
  • Physical device attacks will increase
    South African organizations are uniquely exposed to physical device risk. From mining operations and hospitals to retail branches and municipal offices, devices often operate in uncontrolled environments. As tampering tools become cheaper, attackers can extract firmware, compromise BIOS integrity or physically exfiltrate data. Hardware-level protections including tamper resistance and self-healing firmware are becoming essential, particularly for distributed sectors.
  • Print, IoT and edge devices will be prime targets
    South Africa’s reliance on distributed devices ATMs, POS systems, branch printers, routers and IoT sensors has expanded the attack surface. SABRIC reports that 38% of breaches in 2025 involved compromised peripheral devices. Outdated firmware and limited visibility create entry points for attackers. Future-ready security requires full device lifecycle visibility, automated patching and identity-anchored controls.
  • Quantum resilience will shape procurement
    With quantum-safe cryptography standards now formalized, South African organizations especially in the public sector and critical infrastructure; must plan for long-term cryptographic risk. While quantum attacks are not yet mainstream, “harvest-now, decrypt-later” strategies already exist. Hardware purchased today will still be in use when these threats emerge, making quantum-resilient architecture a procurement priority.
  • Identity and data governance will dominate boardrooms
    As POPIA enforcement matures and the Cybercrimes Act expands obligations, regulators are scrutinizing how data is accessed and protected. Security strategies are shifting toward centralized identity orchestration, provenance verification and continuous data lifecycle oversight. With more than half of local breaches tied to identity compromise, trust must be engineered through unified, simplified access frameworks.
  • SECURING SOUTH AFRICA’S DIGITAL FUTURE

    Cybersecurity in South Africa is no longer just an IT concern it is a business continuity imperative. Attacks are more automated, threats span devices and identities, and the margin for error is shrinking. Organizations that succeed will be those that embed security into hardware, automate recovery and build resilience for the long term. The question is no longer whether attacks will occur, but whether environments are designed to withstand them.

Article Source: Six Cybersecurity Trends Shaping South Africa in 2026 – Africa Outlook Magazine