South African Threat Landscape
A running view of the attacks and vulnerabilities affecting local businesses — refreshed every quarter so you're reacting to what's actually happening, not last year's headlines.
The headline: South Africa is a top target, not a bystander
South Africa remains the most digitally integrated economy on the continent, which also makes it Africa's most attractive target for financially motivated cyber criminals. Across a recent six-month tracking window, South Africa accounted for over 40% of all ransomware attacks and just under 35% of infostealer incidents detected across Africa — the highest of any country on the continent. Phishing remains the most common attack type across the region as a whole, making up roughly a third of all detected attacks.
Ransomware: the cost keeps climbing
South African organisations were attacked an average of roughly 2,145 times per week in the first half of 2026, up 36% year on year, and the financial impact has grown alongside the frequency. The median ransom demanded of South African companies has jumped nearly sixfold to around R17 million, with average recovery costs of roughly R23 million on top of any ransom paid. Only around half of affected companies recovered within a week of an attack.
A meaningful share of South African organisations that do pay a ransom end up paying more than the amount demanded, and roughly two in five encrypted ransomware attacks in South Africa also involve data theft — meaning payment doesn't guarantee the incident stays private, even where data is successfully recovered.
Government and public-sector bodies have been repeatedly targeted alongside private business over the past year, with several high-profile incidents disrupting core services for weeks at a time — a reminder that "too small" or "not a target" is rarely an accurate assumption for any organisation holding personal or financial data.
Which sectors are under the most pressure
Attackers follow opportunity, not headlines. Recent tracking of South African incidents shows retail leading in reported incidents, with technology close behind and manufacturing also a recurring target — a signal that industrial and operational environments are increasingly in scope, not just office IT.
What this means for your business
- Phishing is still the way most attacks start — ongoing staff awareness training remains one of the highest-value controls available.
- Paying a ransom is not a reliable fix — recovery still takes most affected companies longer than a week, and data theft is common even after payment.
- No sector is "safe by size or industry" — retail, technology, manufacturing, government and public services have all been actively targeted in the current cycle.
- Detection speed matters more than ever — the gap between an intrusion and its discovery is usually where the real damage happens.
Want to know where your own environment stands?
A free Cyber Readiness Assessment benchmarks your backups, access control and detection coverage against exactly the threats above.