• 5 minuti
  • Pubblicato

Ransomware paralyses South African organisations as recovery costs climb

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Ransomware paralyses South African organisations as recovery costs climb QWERTYmag © www.qwertymag.it
Ransomware paralyses South African organisations as recovery costs climb © www.qwertymag.it

South African organisations are under constant attack from ransomware, with most incidents traced to stolen credentials and poor security. Even as more companies use backups, recovery is slow and expensive, according to the 2026 Sophos report.

Ransomware attacks on South African organisations now bring immediate and severe disruption. According to Sophos's State of Ransomware in South Africa 2026 report, nearly two-thirds of attacks last year led to data being encrypted-a rate higher than the global average and a sign that the problem is getting worse for local businesses.

While the median ransom demand dropped by 57% to R6.9 million, the average cost to recover from an attack is still over R17 million, not counting the ransom itself. Only 40% of affected organisations managed to recover within a week, the lowest rate among all countries surveyed. For some, the process dragged on for up to six months.

Compromised credentials and weak defences

Most ransomware incidents start with something basic: stolen credentials. These were behind 27% of attacks, letting criminals pose as legitimate users and get around standard security. Vulnerabilities in software made up 25% of cases, and malicious emails caused 22% of breaches. The broader picture is even more concerning-47% of South African respondents said a lack of proper protection was the main reason for their breach, the highest rate in the survey. Another 43% pointed to not enough cybersecurity staff, and 42% said attackers took advantage of known security gaps.

User devices are the most common way in for attacks that don't involve email or phishing, playing a role in 43% of these cases. Exposed applications and systems followed at 38%, with firewalls at 13%. The link between ransomware and identity-based attacks is clear: 85% of South African organisations said their ransomware incident happened alongside their most serious identity attack of the year, much higher than the global average of 67%.

В 2026 году регулятор Южной Африки усилил контроль за последствиями киберинцидентов: Information Regulator выпустил enforcement notice против Central Johannesburg TVET College 20 мая 2026 года и позднее - новые уведомления в августе; отдельно упоминается расследование по инциденту с South African Bureau of Standards после ransomware-атаки 2024 года.
Information Regulator South Africa, Regulatory Authority (source)

Slow recovery and pressure on IT teams

Despite the disruption, 99% of organisations whose data was encrypted managed to recover it. Fewer are paying ransoms-58% paid to get data back, down from 71% the year before. More are using backups, with 54% restoring data this way compared to 35% previously. Data theft has also dropped, with information stolen in 27% of attacks, down from 39% in 2025. Still, recovery is slow. Only 40% of organisations were back up within a week, and 13% took between one and six months. The strain is showing: 52% of IT and cybersecurity staff reported more pressure from leadership, 36% felt more anxious about future attacks, and nearly a quarter saw changes in team leadership.

These trends mirror the disruption seen in other major breaches, such as the Mathspace incident in Australia and New Zealand reported earlier, where attackers exploited known vulnerabilities with serious consequences.

Defence strategies and the role of AI

South Africa's regulators have stepped up in 2026, with the Information Regulator issuing enforcement notices and investigating major incidents, including the ransomware attack on the South African Bureau of Standards. Under the Protection of Personal Information Act (POPIA), the maximum fine is now R10 million, with recent penalties ranging from R100,000 to R5 million. This raises the stakes for organisations that fall short on compliance. In August and September 2026, a series of cyber incidents hit financial and infrastructure firms: Cartrack confirmed a ransomware attack on 26 August, restored its platform by 7:00 the same day, and notified authorities. Early findings showed that customer data-possibly including contact details, banking information, and vehicle telemetry-was at risk.

Other notable cases include EasyEquities and Satrix, which linked their breaches to unauthorised access at a third-party provider, and SA Home Loans, which notified clients even though its own systems were not compromised. The RelyComply incident, widely covered in South African media, involved up to 200GB of client data allegedly accessed by the Dire Wolf ransomware group. In insurance, Hollard denied a direct breach, instead tracing the exposure of personal data from about 45 insurers to a June attack on third-party vendor MIP.

Sophos notes that ransomware attacks often start with weaknesses organisations already know about-unpatched systems, exposed applications, or poorly managed credentials. The company also points to the rise of AI-driven attacks, with some now run entirely by artificial intelligence, making defence even harder. Italian regulators such as Agenzia per la Cybersicurezza Nazionale have also stressed the need for proactive vulnerability management and incident response planning in their latest guidance.

To counter these threats, Sophos recommends strong identity controls, multi-factor authentication everywhere, and regular audits of both human and machine credentials. Endpoint protection should be robust and correctly set up, known vulnerabilities need to be fixed quickly, and email security should include advanced filtering and regular phishing-awareness training. Backups must be tested, stored offline or in formats that can't be changed, and included in a clear incident-response plan.

The evidence shows that South African organisations face not just a technical problem but a systemic one. Gaps in operations and resources leave them open to ongoing ransomware attacks. While more use of backups and fewer ransom payments are positive signs, slow recovery and repeated exploitation of known weaknesses suggest most organisations are still struggling to keep up. Until identity security, skilled staff, and proactive defence become standard, ransomware will continue to shape the reality of South Africa's digital economy.

Articoli correlati