{
  "id": 550452,
  "title": "Ransomware gangs intensify attacks in SA",
  "url": "https://urgent.news/2026/08/11/ransomware-gangs-intensify-attacks-in-sa",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-11T08:56:47.000Z",
  "source": {
    "name": "ITWeb",
    "slug": "itweb",
    "url": "https://www.itweb.co.za/article/ransomware-gangs-intensify-attacks-in-sa/lLn147mQzxP7J6Aa"
  },
  "original_language": "en",
  "account": "Ransomware attacks on South African organizations are becoming faster and more coordinated, with companies having less time to detect and contain breaches before data is stolen and extortion occurs. Lukas van der Merwe, associate director at Cyanre, explained this in an email interview with ITWeb, noting that average attacker dwell time dropped from 117 days in 2024 to just 18 days in 2025. This acceleration is attributed to the industrialization of cyber crime, ransomware-as-a-service platforms, automated tools, and the growing use of artificial intelligence. The result is not only a higher volume of attacks but also shorter attack timelines, leaving organizations with less time to identify malicious activity before significant damage occurs. Cyber crime has shifted towards targeting data rather than just disrupting IT systems, with threat actors increasingly operating like structured businesses focused on data acquisition, control, and leverage. Identity security has become crucial, as breaches often begin with compromised credentials, access-control failures, or identity mismanagement. South African organizations are particularly exposed due to their mature digital economy, uneven levels of cyber resilience, dependence on cloud platforms, and increasing reliance on remote access. These factors, combined with skills shortages, legacy infrastructure, inconsistent security maturity, and weak monitoring, make some organizations easier to compromise. Paying ransomware demands remains a common response among some companies, with 30% of Cyanre's threat actor engagements resulting in payment in 2025. This shift in approach requires organizations to prepare for potential breaches, focusing on resilience rather than prevention. Organisations should assume a breach is possible, create clear decision-making structures, establish communication protocols, and prepare both systems and people for crisis management.",
  "summary": "Local firms are increasingly exposed, as SA combines a relatively mature digital economy with uneven cyber resilience, says Cyanre.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}