Executive summary
Financial services organisations across Africa lose more money to payment diversion than to encryption events, but suffer more operational disruption from ransomware. Both need to be planned for, and they need different controls.
Attack chains are consistent and unglamorous: credential theft, mailbox rule manipulation, patient observation of payment cycles, then a well-timed instruction change at a moment of pressure.
Agent networks and third-party integrations are the least governed part of most institutions' attack surface, and increasingly the entry point.
Sources · [2] UCDP · [5] FEWS NET
Full report
How the loss actually happens
A finance mailbox is compromised through phishing or credential reuse. The intruder studies invoice cadence and language for weeks, sets rules to hide selected replies, then submits a change of bank details at a plausible moment, often during a staff absence.
Recovery depends on speed: interbank recall requests placed within hours have a meaningfully better outcome than those placed the following day. Every institution should know, in advance, who makes that call and how.
Sources · [7] GDELT Project · [10] AlienVault OTX
Control set
Mandatory callback verification on a previously held number for any bank detail change; segregation of duties on payment release; alerting on mailbox rule creation and impossible-travel authentication; phishing-resistant MFA for finance and administrative accounts.
For ransomware: immutable and offline backup copies, quarterly restore tests measured against a stated recovery time objective, network segmentation between core systems and general corporate IT, and privileged access management for administrators and vendors.
Sources · [8] Institute for Security Studies (ISS Africa) · [11] URLhaus / AbuseIPDB
Third parties and agent networks
Integrations with aggregators, switch providers and agent platforms should be governed with the same rigour as internal systems: scoped credentials, rate limiting, monitoring and contractual security obligations with audit rights.
Agent onboarding and periodic re-vetting is a fraud control. Where agents handle cash and customer identity, the security programme must include physical and personnel measures, not only technical ones.
Sources · [3] UN OCHA / ReliefWeb · [6] NASA FIRMS / Copernicus
Incident readiness
Maintain a tested playbook covering technical containment, regulator notification, customer communication and law enforcement engagement, with named owners and out-of-hours contacts. Rehearse it with the executive team, because the decisions that matter in the first six hours are commercial, not technical.
Sources · [8] Institute for Security Studies (ISS Africa) · [11] URLhaus / AbuseIPDB
Key findings
- Mailbox rules that hide replies from finance staff are present in the majority of BEC cases and are trivially detectable if anyone is looking for them.
- Supplier and payroll change requests arriving near a payment deadline are the standard pretext; time pressure is the exploit, not the technology.
- Microfinance institutions and savings cooperatives are targeted because they hold real money with limited security engineering capacity.
- Ransomware recovery time in the sector is dominated by restoration testing gaps, not by the encryption itself.
- Insider-facilitated fraud in agent networks and branch operations remains a significant loss channel that pure technical controls do not address.
Analyst assessment
We assess with high confidence that out-of-band verification of payment instruction changes is the single highest-return control available to institutions in this sector.
We assess with moderate confidence that attacks against fintech and mobile money integrations will grow faster than attacks against traditional bank cores.
Regulatory expectation is rising faster than sector capability, which will produce enforcement actions against institutions that survive the incident but fail the reporting.
Related reports
Footnotes & sources
- [1] ACLED — Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
- [2] UCDP — Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
- [3] UN OCHA / ReliefWeb — Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
- [4] GDACS — Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
- [5] FEWS NET — Food security outlooks and alertsL2 Early warning · reliability A
- [6] NASA FIRMS / Copernicus — Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
- [7] GDELT Project — Global media event and tone monitoringL5 Strategic · reliability C
- [8] Institute for Security Studies (ISS Africa) — Regional political and security analysisL5 Strategic · reliability B
- [9] INGO ADVISORY analyst desk — Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
- [10] AlienVault OTX — Open threat exchange indicatorsL4 Cyber · reliability B
- [11] URLhaus / AbuseIPDB — Malicious infrastructure and abuse reportingL4 Cyber · reliability B
Supporting capability statement
Horn of Africa security capability pack
Download the experience summary, applied risk frameworks and sample operational brief supporting this country threat assessment.
Free operational toolkit
Act on this assessment
Six free operational tools for NGO and charity teams — no sign-up, nothing leaves your browser.
- Travel risk authorisationRisk-tiered approval form with control verification before movement is signed off.
- Vehicle & convoy check13-point pre-departure inspection with go / no-go clearance logic.
- Safeguarding / PSEA referralAnonymised referral log for PSEA and misconduct concerns.
- Cyber hygiene assessmentScored self-assessment producing a prioritised remediation workplan.
- Staff accountability roll callReal-time headcount and status tracking during an incident.
- Endurance calculatorContingency stock planning for water, food, fuel and cash.