South Africa has the highest cybercrime burden on the continent, and the numbers behind that ranking keep getting harder to ignore. More than half of South African firms report being hit by ransomware in the past year, commentators describing the country as "under cyber-siege" this week, with AI tools increasingly used by attackers to scale phishing and social-engineering campaigns far beyond what a human-run operation could manage on its own. Average ransom demands against South African institutions now run around R3.2 million, with some organised groups demanding as much as R13.6 million from a single target.
A newer malware strain called Agenda illustrates how the threat has evolved: it targets healthcare and educational institutions specifically, and is sophisticated enough to override antivirus defences, change account passwords, encrypt data and re-enter systems automatically using the new credentials it creates. Security researchers describe South Africa's combination of advanced digital adoption and comparatively weak security investment as exactly the profile ransomware-as-a-service operators look for: a country wealthy and connected enough to pay a meaningful ransom, but under-defended enough to make getting in easy.
The country's most instructive cautionary tale is still the 2024 LockBit 3.0 attack on the Government Pensions Administration Agency, which knocked systems offline for four months and forced a complete infrastructure rebuild before service was restored. Attackers stole and published a 668GB archive covering 168,000 individuals, including personal information belonging to President Cyril Ramaphosa, and the fund's chief executive was later dismissed following a disciplinary hearing. The agency manages more than R2.38 trillion in assets for 1.7 million active members.
The exposure gap is structural as much as technical: South African government agencies put less than 5% of IT budgets toward cybersecurity, compared with roughly 15% in the corporate sector, and many public systems still run on infrastructure that is 20 to 30 years old. Nationally, only 40% of South African companies manage to resume operations within a week of a cyberattack, well below the 55% global average — a gap analysts attribute less to any single missing tool than to years of underinvestment in the basics.

