Executive summary
The dominant loss events across African organisations remain business email compromise and ransomware, both of which exploit process and identity weaknesses rather than novel technical capability.
Public sector and health institutions continue to be disproportionately affected because legacy estates, thin staffing and constrained budgets leave patching and backup validation undone.
Politically motivated intrusion and defacement activity tracks regional disputes and election cycles, generating noise that can mask more consequential intrusions running in parallel.
Sources · [7] GDELT Project · [10] AlienVault OTX
Full report
Threat activity this quarter
Ransomware pressure continues to concentrate on organisations with flat networks, unmanaged remote access and unvalidated backups. Initial access is typically through exposed remote services, credential reuse or a compromised supplier account.
Hacktivist defacement and distributed denial of service activity tracks political flashpoints. Its direct damage is usually limited, but it consumes response capacity and can accompany more serious activity.
Sources · [4] GDACS · [7] GDELT Project
Controls that change outcomes
Phishing-resistant multi-factor authentication on email and remote access; out-of-band verification for any change to supplier bank details; offline, restore-tested backups; and rapid removal of internet-exposed management interfaces. These four cover the majority of realistic incidents.
Test the incident response plan against a scenario that includes exfiltration and regulatory notification timelines. A plan that only addresses restoration is a plan for half of the problem.
Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus
Regulatory and legal exposure
Map the personal data an organisation holds against the jurisdictions that regulate it, and confirm who is legally accountable for notification in each. Multi-country operations frequently discover during an incident that no one owns this.
Cross-border data transfer, cloud region selection and vendor contract terms should be settled as part of architecture decisions rather than renegotiated under pressure.
Sources · [4] GDACS · [7] GDELT Project
Indicators and watch items
Watch for: leak-site listings naming African organisations in your sector; credential dumps affecting your domains; supplier breach notifications; unusual authentication from new locations against finance-team accounts; changes in mobile money fraud typologies affecting your payout channels.
Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus
Key findings
- Business email compromise against supplier payment processes remains the highest-frequency financial loss event and is materially under-reported for reputational reasons.
- Ransomware operators increasingly exfiltrate before encrypting, so backup quality alone no longer bounds the consequences of an incident.
- Mobile money and agent-banking fraud drives a large volume of lower-value incidents with significant cumulative cost and customer harm.
- Third-party and managed service provider compromise is a recurring route into otherwise well-defended organisations.
- Data protection regulation across the continent, Nigeria, Kenya, South Africa, Egypt, Morocco and others, now imposes real notification obligations that must be planned for before an incident, not during one.
Analyst assessment
We assess with high confidence that BEC and ransomware will remain the leading loss categories for African organisations through 2027.
We assess with moderate confidence that regulatory enforcement of breach notification will increase, raising the cost of unprepared incident response.
The most likely material incident for a mid-sized organisation is a payment diversion following a mailbox compromise, not a targeted intrusion by a sophisticated actor.
Related reports
Footnotes & sources
- [1] ACLED — Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
- [2] UCDP — Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
- [3] UN OCHA / ReliefWeb — Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
- [4] GDACS — Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
- [5] FEWS NET — Food security outlooks and alertsL2 Early warning · reliability A
- [6] NASA FIRMS / Copernicus — Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
- [7] GDELT Project — Global media event and tone monitoringL5 Strategic · reliability C
- [8] Institute for Security Studies (ISS Africa) — Regional political and security analysisL5 Strategic · reliability B
- [9] INGO ADVISORY analyst desk — Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
- [10] AlienVault OTX — Open threat exchange indicatorsL4 Cyber · reliability B
- [11] URLhaus / AbuseIPDB — Malicious infrastructure and abuse reportingL4 Cyber · reliability B
Supporting capability statement
Horn of Africa security capability pack
Download the experience summary, applied risk frameworks and sample operational brief supporting this country threat assessment.
Free operational toolkit
Act on this assessment
Six free operational tools for NGO and charity teams — no sign-up, nothing leaves your browser.
- Travel risk authorisationRisk-tiered approval form with control verification before movement is signed off.
- Vehicle & convoy check13-point pre-departure inspection with go / no-go clearance logic.
- Safeguarding / PSEA referralAnonymised referral log for PSEA and misconduct concerns.
- Cyber hygiene assessmentScored self-assessment producing a prioritised remediation workplan.
- Staff accountability roll callReal-time headcount and status tracking during an incident.
- Endurance calculatorContingency stock planning for water, food, fuel and cash.