Kathy Gibson reports – Phishing is still the biggest cybersecurity threat in Africa, accounting for 17,5% of the cyberattacks on the continent.

This is according to the ESET H1 2026 Threat Report, which found that the phishing threat is elevated in South Africa, where it jumps to 45%.

“In South Africa there is more to monetise,” explains Tony Anscombe, chief security evangelist at ESET. “So phishing attacks have a better success rate in South Africa.

“This is a business, and they attack where people are more likely to pay.”

As an example, he points to the US, where the incidence of phishing is well over 50%.

Allan Juma, lead cybersecurity engineer at ESET, points out that cryptojacking is also on the rise in Africa, where hackers use victims’ systems to mine cryptocurrency.

The threat is usually downloaded via illegal streaming sites, with the majority – 90% to 94% in Africa – coming from a single site, he adds.

AI looms large in any cybersecurity discussion.

Anscombe explains that AI skills are essentially reusable pieces of code that perform specific tasks according to specialised playbooks.

“If you have an AI agent,  you have to think of it like an employee. You task it to do something so it should live within the same privileges and guardrails as any other employee.”

The AI skills include those for developers or for employees. While Anscombe assumes developers understand cybersecurity risks, there is more danger from general employees.

“There are a lot of useful skills that people may be downloading and adding to their agents,” he points out. “This unverified code is a potential problem.”

Since March, ESET has scanned 900 000 AI skills downloaded by users, finding 25 000 that are suspicious and 3 000 that are outright malicious.

He points out that not all AI skills are written to be malicious – but someone other than the author could use it nefarious purposes.

A more dangerous AI threat that has been identified is a self-modifying skill that could be brought in to perform a specific task that then goes rogue.

“You need to have an AI policy in place,” Anscombe says. “If you don’t, you need to.”

Ransomware may have been overshadowed somewhat by AI, but it is still a massive threat in Africa.

Juma points out that the biggest threat on the continent is still the generic screenlocker – or scareware – accounting for 44,7% of incidents.

This argues that opportunistic cybercriminals are still making the most money from unsophisticated users, who take threats seriously and pay up to get their screens unlocked. Of course, they don’t ger unlocked even when the ransom has been paid.

There are also more professional ransomware actors taking advantage of companies and individual in Africa, more prevalent in South Africa.

Jume advises victims to avoid paying ransomware. And Anscombe points out that cybersecurity companies or law enforcement often have decrypters and could unlock attack.

Among the top ransomware groups in Africa are DragonForce, Qilin and The Gentlemen.

Juma explains that these are also the leading groups worldwide, which is a concern for the continent as it shows users are being targeted by the most sophisticated threat actors.

Another leading ransomware group is WannaCryptor, a variation of 2017’s original ransomware WannaCry. Anscombe believes this is still active in Africa because there are still older, unpatched machines out there.

Industries like mining and healthcare are particularly prone to having older systems in use – often on the same system as the rest of the network that could include the most modern OT machines.

A new threat is coming from endpoint detection and response (EDR) killers, which allows encryption software to run more efficiently.

EDR killers operate in a business model, says Anscombe. Ransomware as a service groups create the tools to gain data, which is then sold to affiliates who identify what is worth exfiltrating, and then pass these on to operators.

“In fact, it’s a channel model,” he explains.