South Africa was the 42nd most breached country in the world during the first half of the year, with 359 600 leaked accounts, according to the latest data from cybersecurity firm Surfshark.
Globally, a total of 313,4-million accounts were breached, with the US ranking first and amounting to 29% of all breaches from January through June. France takes second place, while Brazil is third, followed by India and the UK.
Surfshark’s data also highlights a notable regional shift: Europe surpassed North America in the number of breached accounts during the previous quarter. In Q2 2026, one in three breached accounts worldwide came from Europe – and 58% of those within the region were linked to France. In addition, four out of five countries with the highest breach density (number of leaked accounts per 1 000 residents) are also European: First is, again, France, then Poland, the US, Portugal, and Lithuania.
“Information taken in breaches years ago can remain in circulation for a long time, resurfacing in new fraud schemes, and used to target people long after the original incident,” says Tomas Stamulis, chief security officer at Surfshark. “The same is true for data being stolen today: even if it is not abused immediately, it can still come back years later in the form of account takeovers, identity abuse, scams, and financial theft.”
Since 2004, South Africa has ranked second in Africa, with 45,8-million compromised user accounts. A total of 13,4-million unique emails were breached from South Africa and 22,9-million passwords were leaked together with South African accounts, putting 50% of breached users in danger of account take over that might lead to identity theft, extortion, or other cybercrimes.
Statistically, 70 out of 100 South African people have been affected by data breaches.
In order to stay safe online and limit your exposure, Tomas Stamulis shares his tips:
- As a general rule, treat all your personal information as sensitive by default and disclose it only when absolutely required.
- Share your real personal details only when there is a genuine, necessary reason, such as completing official or legally required forms.
- For everything else, limit your exposure by using an alias, a secondary email address, or an email-masking service.