Urgent.News

What's breaking now, across thousands of outlets.

Tech

Ransomware gangs intensify attacks in SA

Local firms are increasingly exposed, as SA combines a relatively mature digital economy with uneven cyber resilience, says Cyanre.

Ransomware gangs intensify attacks in SA

Ransomware attacks on South African organizations are becoming faster and more coordinated, with companies having less time to detect and contain breaches before data is stolen and extortion occurs. Lukas van der Merwe, associate director at Cyanre, explained this in an email interview with ITWeb, noting that average attacker dwell time dropped from 117 days in 2024 to just 18 days in 2025.

This acceleration is attributed to the industrialization of cyber crime, ransomware-as-a-service platforms, automated tools, and the growing use of artificial intelligence. The result is not only a higher volume of attacks but also shorter attack timelines, leaving organizations with less time to identify malicious activity before significant damage occurs.

Cyber crime has shifted towards targeting data rather than just disrupting IT systems, with threat actors increasingly operating like structured businesses focused on data acquisition, control, and leverage. Identity security has become crucial, as breaches often begin with compromised credentials, access-control failures, or identity mismanagement.

South African organizations are particularly exposed due to their mature digital economy, uneven levels of cyber resilience, dependence on cloud platforms, and increasing reliance on remote access. These factors, combined with skills shortages, legacy infrastructure, inconsistent security maturity, and weak monitoring, make some organizations easier to compromise.

Paying ransomware demands remains a common response among some companies, with 30% of Cyanre's threat actor engagements resulting in payment in 2025. This shift in approach requires organizations to prepare for potential breaches, focusing on resilience rather than prevention. Organisations should assume a breach is possible, create clear decision-making structures, establish communication protocols, and prepare both systems and people for crisis management.

Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at itweb.co.za →

More in Tech

IP Geolocation Is Wrong — Why VPN Detection Fails 90% Of Us

security, #api, #cybersecurity, #webdev Last Tuesday, a paying customer in Austin couldn't finish checkout. Our fraud engine had flagged her IP as a "high-risk VPN." She was on Spectrum. At home.

  • Customer in Austin faced checkout issues due to flagged VPN IP.
  • Stale database incorrectly marked /24 range as datacenter.
  • Modern IP checks should offer reverse-IP discovery and VPN flags.

More from Tuesday 11 August →