Report warns Africa faces rapid surge in cyber threats

  • Africa is experiencing a major rise in cyber threats
  • Groups linked to China, Russia and Iran have widened their presence across African networks
  • African governments have also been drawn into wider Iranian and Russian cyber operations

Africa is experiencing a major rise in cyber threats as global political tensions, rapid digital growth and advances in artificial intelligence create new opportunities for attackers.

The 2025 State of Cyber Security Report says the continent has become a key target for cyber-espionage, disinformation, ransomware and large-scale credential theft.

Groups linked to China, Russia and Iran have widened their presence across African networks, taking advantage of weak security in government systems and critical infrastructure.

One of the most notable developments is the spread of Chinese state-linked cyber espionage. The Sharp Dragon campaign infiltrated African government institutions using Cobalt Strike tools to hide inside networks, extract sensitive data and maintain long-term access.

Other China-connected actors, such as Water Sigbin 8220, targeted outdated Oracle WebLogic systems, while larger Chinese operations used hijacked IoT devices to attack telecom operators and government platforms.

African governments have also been drawn into wider Iranian and Russian cyber operations. These groups targeted ministries, communications bodies and key infrastructure to gather intelligence, disrupt public services and secure lasting access inside national networks.

The report says this places Africa firmly in the middle of a global cyber struggle between major powers.

AI-driven disinformation has also become a serious concern, especially during elections. With more than 15 African elections taking place between 2023 and 2024, foreign actors spread deepfake videos, fake social media content and divisive political messages to influence voters. The report says AI tools were used in around a third of elections globally, including in Africa, where they increased political and social tensions in several countries.

Ransomware attacks are rising sharply, particularly against Africa’s healthcare systems and public institutions, many of which rely on outdated cyber tools. Attackers increasingly steal data rather than encrypt systems, then threaten to leak it unless paid. Groups such as RansomHub, BianLian, Qilin and Medusa have targeted medical records and government data, damaging public trust.

Infostealers are also spreading quickly. These tools capture passwords, cookies and cloud logins, mostly from personal devices. With over 70% of compromised devices worldwide being personal, African companies face a greater risk when attackers reuse stolen credentials to enter corporate networks. Infostealers like Lumma, RedLine and StealC have been used to breach fintech firms, telecom providers and government portals.

Hacktivist groups, often linked to Iranian or Russian interests, have increased attacks on African governments through website defacement, data leaks and destructive malware. Meanwhile, telecom networks have become major targets for Chinese-linked groups aiming to intercept data or install surveillance points.

The report concludes that Africa is now central to global cyber operations and must treat cybersecurity as a national security priority as threats continue to rise.

No Comments

Sorry, the comment form is closed at this time.

1