Cyberattacks in Africa are experiencing an alarming rise. This includes a 14% increase in spyware-related incidents and a 26% increase in password-stealing malware attacks, according to Kaspersky.
Priority Cyberattack Targets
Critical Infrastructure: Attacks against electricity companies (Cameroon), telecommunications (Namibia, Uganda), and healthcare laboratories (South Africa).
Financial Sector: Widespread bank fraud in West Africa, and 85% of mobile banking services are used, leaving users exposed.
Governments: Massive hacks targeting South African agencies (1,450 attacks/week in 2024), including the public pension fund (85 billion USD).
Raising risk awareness
In the B2C sector, the growth of online financial services, combined with a relatively low level of digital literacy, makes individuals particularly exposed to risks.
In 2024, Kaspersky detected 131.5 million online threats on the African continent. Kenya ranks first with nearly 20 million cases, closely followed by South Africa (17 million) and Morocco (12.6 million). These risks, which increased by 1.2% compared to 2023, primarily affect businesses.
In addition to cyberattacks, a sharp increase in local malware has been observed, often transmitted via external devices such as USB drives: +169% in Nigeria, +86% in Ethiopia, +32% in South Africa, +11% in Senegal, and +9% in Morocco.
Aggravating factors
Regional disparities: Kenya, Mauritius, and Senegal have national strategies, unlike Burundi or the Central African Republic.
Technological challenges: 1 in 9 users in Nigeria installs infected Android apps.
New criminal tools: leveraging AI for phishing and sophisticated Trojans such as those in the 3CXDesktop app.
How can African businesses protect themselves?
African businesses can adopt a multifaceted approach to strengthen their cybersecurity in the face of rising attacks.
Strong authentication: Systematic implementation of complex passwords and two-factor authentication, particularly for vulnerable mobile banking services.
Software Updates: Rigorous system maintenance to address security vulnerabilities, a practice often overlooked according to audits.
Data Encryption: Protection of sensitive information using advanced encryption protocols.
Response Plans: Development of emergency protocols to limit damage during incidents, including offline backups.
Access Control: Restricting access to sensitive data through least privilege policies.
AI Solutions: Deployment of systems capable of detecting behavioral anomalies and automating responses.
Next-Generation Firewalls: Combination of network filtering and analytical monitoring to counter sophisticated malware.
Intrusion Detection: Real-time monitoring of suspicious activity on corporate networks.
Regulatory Compliance: Gradual alignment with standards such as the emerging African GDPR, despite regional legislative disparities.
Perspectives and Solutions
The African cybersecurity market is expected to reach USD 2.7 billion by 2025. Countries are strengthening their legislative frameworks, such as South Africa with its military cyber command, while the Cyber Africa Forum 2025 highlights the urgency of transnational collaborations. User awareness remains a key issue in the face of financial scams and ransomware.