Reports & Briefings

Cyber Threat Bulletin — Africa Q2

Quarterly cyber threat landscape across African markets with sector-specific mitigation guidance.

Author
Mowlid Ali
Published
Q2 2026
Country / region
Africa-wide
Threat category
Ransomware · BEC · Governance failure
Length
22 pages
CyberAfrica-wide
Listen · 1 minReady to play · about 1 min

Executive summary

Cyber risk across African markets is overwhelmingly a governance problem rather than a technology problem. The dominant loss events — business email compromise, ransomware and third-party breach — exploit process gaps, not exotic capability.

This bulletin summarises the quarter's observed activity and translates it into board-level governance actions.

Sources · [2] UCDP · [5] FEWS NET

Full report

Governance actions

Enforce out-of-band verification for all payment instruction changes. Review third-party and partner access quarterly. Test restore-from-backup, not just backup completion. Rehearse incident response with finance and communications in the room, not only IT.

Sources · [4] GDACS · [7] GDELT Project

Key findings

  • Business email compromise remains the highest-frequency, highest-loss event type for organisations operating in the region.
  • Ransomware operators continue to target public health, education and logistics entities with weak backup discipline.
  • Third-party and implementing-partner access is the most common unmanaged pathway into NGO environments.
  • Mandatory data protection regimes are maturing faster than most in-country compliance functions.

Analyst assessment

We assess with high confidence that governance-led controls — payment verification, access review, backup testing and incident rehearsal — will prevent more loss than additional security tooling for most organisations in this region.

Related reports

Footnotes & sources

  1. [1] ACLED Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
  2. [2] UCDP Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
  3. [3] UN OCHA / ReliefWeb Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
  4. [4] GDACS Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
  5. [5] FEWS NET Food security outlooks and alertsL2 Early warning · reliability A
  6. [6] NASA FIRMS / Copernicus Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
  7. [7] GDELT Project Global media event and tone monitoringL5 Strategic · reliability C
  8. [8] Institute for Security Studies (ISS Africa) Regional political and security analysisL5 Strategic · reliability B
  9. [9] INGO ADVISORY analyst desk Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
  10. [10] AlienVault OTX Open threat exchange indicatorsL4 Cyber · reliability B
  11. [11] URLhaus / AbuseIPDB Malicious infrastructure and abuse reportingL4 Cyber · reliability B
  12. [12] OpenSanctions Sanctions, PEP and enforcement screening dataL5 Strategic · reliability A

Start a confidential conversation

Tell us about your operations and where you’re operating. We’ll propose next steps within one working day.