Research & Analysis

Cyber Threat Bulletin, Africa Q3

Quarterly read on ransomware pressure against African enterprises and public bodies, business email compromise economics, mobile money fraud and politically motivated intrusion.

Author
Mowlid Ali
Published
Q3 2026
Country / region
Africa-wide
Threat category
Ransomware · BEC · Hacktivism
Length
24 pages
CyberNigeriaKenyaSouth AfricaEgyptMoroccoGhana
Listen · 3 minReady to play · about 3 min

Executive summary

The dominant loss events across African organisations remain business email compromise and ransomware, both of which exploit process and identity weaknesses rather than novel technical capability.

Public sector and health institutions continue to be disproportionately affected because legacy estates, thin staffing and constrained budgets leave patching and backup validation undone.

Politically motivated intrusion and defacement activity tracks regional disputes and election cycles, generating noise that can mask more consequential intrusions running in parallel.

Sources · [7] GDELT Project · [10] AlienVault OTX

Full report

Threat activity this quarter

Ransomware pressure continues to concentrate on organisations with flat networks, unmanaged remote access and unvalidated backups. Initial access is typically through exposed remote services, credential reuse or a compromised supplier account.

Hacktivist defacement and distributed denial of service activity tracks political flashpoints. Its direct damage is usually limited, but it consumes response capacity and can accompany more serious activity.

Sources · [4] GDACS · [7] GDELT Project

Controls that change outcomes

Phishing-resistant multi-factor authentication on email and remote access; out-of-band verification for any change to supplier bank details; offline, restore-tested backups; and rapid removal of internet-exposed management interfaces. These four cover the majority of realistic incidents.

Test the incident response plan against a scenario that includes exfiltration and regulatory notification timelines. A plan that only addresses restoration is a plan for half of the problem.

Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus

Regulatory and legal exposure

Map the personal data an organisation holds against the jurisdictions that regulate it, and confirm who is legally accountable for notification in each. Multi-country operations frequently discover during an incident that no one owns this.

Cross-border data transfer, cloud region selection and vendor contract terms should be settled as part of architecture decisions rather than renegotiated under pressure.

Sources · [4] GDACS · [7] GDELT Project

Indicators and watch items

Watch for: leak-site listings naming African organisations in your sector; credential dumps affecting your domains; supplier breach notifications; unusual authentication from new locations against finance-team accounts; changes in mobile money fraud typologies affecting your payout channels.

Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus

Key findings

  • Business email compromise against supplier payment processes remains the highest-frequency financial loss event and is materially under-reported for reputational reasons.
  • Ransomware operators increasingly exfiltrate before encrypting, so backup quality alone no longer bounds the consequences of an incident.
  • Mobile money and agent-banking fraud drives a large volume of lower-value incidents with significant cumulative cost and customer harm.
  • Third-party and managed service provider compromise is a recurring route into otherwise well-defended organisations.
  • Data protection regulation across the continent, Nigeria, Kenya, South Africa, Egypt, Morocco and others, now imposes real notification obligations that must be planned for before an incident, not during one.

Analyst assessment

We assess with high confidence that BEC and ransomware will remain the leading loss categories for African organisations through 2027.

We assess with moderate confidence that regulatory enforcement of breach notification will increase, raising the cost of unprepared incident response.

The most likely material incident for a mid-sized organisation is a payment diversion following a mailbox compromise, not a targeted intrusion by a sophisticated actor.

Related reports

Footnotes & sources

  1. [1] ACLED Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
  2. [2] UCDP Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
  3. [3] UN OCHA / ReliefWeb Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
  4. [4] GDACS Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
  5. [5] FEWS NET Food security outlooks and alertsL2 Early warning · reliability A
  6. [6] NASA FIRMS / Copernicus Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
  7. [7] GDELT Project Global media event and tone monitoringL5 Strategic · reliability C
  8. [8] Institute for Security Studies (ISS Africa) Regional political and security analysisL5 Strategic · reliability B
  9. [9] INGO ADVISORY analyst desk Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
  10. [10] AlienVault OTX Open threat exchange indicatorsL4 Cyber · reliability B
  11. [11] URLhaus / AbuseIPDB Malicious infrastructure and abuse reportingL4 Cyber · reliability B

Supporting capability statement

Horn of Africa security capability pack

Download the experience summary, applied risk frameworks and sample operational brief supporting this country threat assessment.

Independent research

Explore the research

Open-source analysis of security developments, operational risk and emerging threats across Africa, with a focus on East Africa and the Horn of Africa.