By: Thobeka Ngema
South Africa has become the continent’s epicentre for cybercriminal activity, according to Interpol’s latest African Cyberthreat Assessment Report.
While the report highlights alarming statistics, such as South Africa accounting for 92% of all ransomware detections in Africa, industry experts warn that the true crisis lies not just in the frequency of attacks, but in a systemic failure to defend against them.
“South Africa accounted for 92% of all ransomware detections in Africa by TrendAI, with incidents affecting critical infrastructure such as the South African Weather Service, South African Airways, and Namibia’s Paratus Telecom,” the report read.
It said that regarding Distributed Denial-of-Service (DDoS) attacks, South Africa alone recorded 213 523 attacks, a single incident reaching 312 Gbps – dwarfing all other regions.
Moreover, phishing was rampant, with South Africa accounting for almost 40% of all African phishing detections, followed by Mauritius at 22%, according to SOCRadar.
The report said that despite mature regulatory frameworks like South Africa’s Cybersecurity Act and Mauritius’ Digital Transformation Blueprint, the region remains vulnerable to AI-enabled threats. Trends like Zambian scam centres and South African deepfake-sextortion highlight how advanced infrastructure often coexists with systemic exploitation.
“South Africa accounted for 92% of all ransomware detections in Africa, according to TrendAI data,” the report read.
In 2025, TrendAI data indicated that 70% of Business E-mail Compromise detections originated in South Africa and 29% from Nigeria. TrendAI also recorded 600 000 sextortion detections in Africa in 2025, with the majority originating from South Africa (30%), Kenya (13%), Côte d’Ivoire (11%), Ethiopia (8%), and Angola (4%).
Additionally, the Shadowserver Foundation identified more than 6 000 exploitable vulnerabilities across Africa in 2025, with the highest concentrations in South Africa (43.6%), Kenya, and Nigeria, the same countries with the largest internet user bases.
Specialist investigator Anthony Boucher said: “South Africa is ground zero for cybercrime in Africa. 92% of ransomware attacks? That’s not a statistic – that’s a crisis. We’re the most connected country on the continent, and we’ve basically rolled out the red carpet for criminals.”
Boucher said the 43% vulnerability figure tells him the country is not even doing the basics. Unpatched systems are being exploited.
He said the AI part is most shocking. Criminals are using deepfakes and automated attacks, while South African investigators lack the skills to spot it.
“The SA Weather Service attack should have been a wake-up call. They disrupted aviation systems – not for money, but for chaos,” said Boucher, who is the Mike Bolhuis’ Specialised Security Services, Cybercrimes Division national head.
He said that while good laws exist on paper, implementation is almost non-existent.
“Our police don’t have the tools or training. Some stations don’t even have working computers. How do you investigate a digital crime without digital forensics?” Boucher asked.
He said criminals exploit the lack of 24/7 monitoring by finding targets on weekends. Furthermore, critical information silos persist: banks cannot share real-time fraud data with police without a court order, causing delays that allow funds to be siphoned off before law enforcement can act.
“And we’ve got a massive skills gap. Crypto-tracing, malware analysis, AI detection – we’re short-staffed and under-trained,” Boucher said.
“The solution is for the government to cooperate with the private sector, and for the law to allow for the sharing of protected information on a basis of urgency. Training and resources should be a priority for law enforcement; without it, South Africa will continue to be a sitting duck.”
Professor of cybersecurity at the University of Johannesburg Basie von Solms said there is nothing dramatically new in the report. Many of the things reported on have been well-known for many years, but nothing is being done about it.
Von Solms said the major problem for cybercrime is the lack of political will from the government as revealed by Auditor-General reports from the past five years which consistently show that 50–70% of audited government IT systems contain known, unfixed vulnerabilities. A primary obstacle to addressing these security failures is the persistent lack of political will to act on these findings.
“It may be that there’s no money to do it, then we shouldn’t have the systems,” Von Solms said, adding that the Auditor-General reports that South Africa is using outdated systems and in some cases, the licence has expired.
Secondly, he said there is a lack of cybersecurity awareness from the general public.
“The government, I think, has got a duty because if you look at the Interpol report, if you look at cybercrime using attack methods like phishing, sextortion, these are all attack methods which are based on the fact that the end user does not recognise it, is not aware of the risk of using cyberspace,” Von Solms said.
Article Source: https://iol.co.za/mercury/news/2026-08-06-sa-is-africas-cybercrime-epicentre/



