Skip to content
Research & Analysis

Cyber Threat Bulletin, Africa Q2

Quarterly cyber threat landscape across African markets with sector-specific mitigation guidance.

Author
Mowlid Ali
Published
Q2 2026
Country / region
Africa-wide
Threat category
Ransomware · BEC · Governance failure
Reliability
Not separately rated
Confidence
See assessment limitations
Length
22 pages
CyberAfrica-wide
Listen · 1 minReady to play · about 1 min

Executive summary

Cyber risk across African markets is overwhelmingly a governance problem rather than a technology problem. The dominant loss events, business email compromise, ransomware and third-party breach, exploit process gaps, not exotic capability.

This bulletin summarises the quarter's observed activity and translates it into board-level governance actions.

Sources · [2] UCDP · [5] FEWS NET

Full report

Governance actions

Enforce out-of-band verification for all payment instruction changes. Review third-party and partner access quarterly. Test restore-from-backup, not just backup completion. Rehearse incident response with finance and communications in the room, not only IT.

Sources · [4] GDACS · [7] GDELT Project

Key findings

  • Business email compromise remains the highest-frequency, highest-loss event type for organisations operating in the region.
  • Ransomware operators continue to target public health, education and logistics entities with weak backup discipline.
  • Third-party and implementing-partner access is the most common unmanaged pathway into NGO environments.
  • Mandatory data protection regimes are maturing faster than most in-country compliance functions.

Analyst assessment

We assess with high confidence that governance-led controls, payment verification, access review, backup testing and incident rehearsal, will prevent more loss than additional security tooling for most organisations in this region.

Related reports

Footnotes & sources

  1. [1] ACLED: Armed Conflict Location & Event Data, Africa event recordsL1 Conflict · reliability A
  2. [2] UCDP: Uppsala Conflict Data Program, organised violence datasetL1 Conflict · reliability A
  3. [3] UN OCHA / ReliefWeb: Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
  4. [4] GDACS: Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
  5. [5] FEWS NET: Food security outlooks and alertsL2 Early warning · reliability A
  6. [6] NASA FIRMS / Copernicus: Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
  7. [7] GDELT Project: Global media event and tone monitoringL5 Strategic · reliability C
  8. [8] Institute for Security Studies (ISS Africa): Regional political and security analysisL5 Strategic · reliability B
  9. [9] Mazin Intel analyst desk: Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
  10. [10] AlienVault OTX: Open threat exchange indicatorsL4 Cyber · reliability B
  11. [11] URLhaus / AbuseIPDB: Malicious infrastructure and abuse reportingL4 Cyber · reliability B
  12. [12] OpenSanctions: Sanctions, PEP and enforcement screening dataL5 Strategic · reliability A

Independent research

Explore the research

Open-source analysis of security developments, operational risk and emerging threats across Africa, with a focus on Africa.

For shipowners, insurers and risk teams

Need a decision-ready briefing on this risk?

Country, port and voyage briefings with named sources, stated confidence and clear evidence limits.