Africa has emerged as one of the world’s primary battlegrounds for global cybercriminals, enduring a wave of sophisticated attacks that are outpacing the continent’s rapid digital expansion.
A new report by Check Point Research reveals that African organizations are weathering close to 3,000 cyber-attacks per week a figure that sits well above the global average of 2,055 and positions Africa as the second most targeted region on earth, trailing only Latin America.
The crisis is hitting the continent’s oil and financial heavyweights the hardest. Organizations in Angola faced an average of 4,046 weekly attacks in May, while Nigerian institutions recorded 3,941. Both countries are experiencing double the global average of corporate cyber assaults. East and Southern African economic engines are also under pressure; Kenya recorded 2,443 weekly attacks per organization, while South Africa averaged 1,738.
The Shift to Corporate Extortion
The surge comes as international syndicate strategies shift from causing generalized network disruption to executing highly targeted, financially motivated extortion campaigns. This pivot makes the threat environment significantly harder to predict and far more economically damaging when breaches occur.
Ransomware is the primary engine behind this trend. Globally, publicly reported ransomware attacks jumped 48% year-on-year to 698 incidents in May the sharpest annual increase recorded so far in 2026. Within Africa, hackers are systematically profiling targets, focusing their energy on the business services and banking sectors.
“Ransomware groups continue to apply sustained pressure on African organizations,” said Hendrik de Bruin, Head of Security Consulting for Africa at Check Point Software. “The increasing focus is on organizations capable of paying extortion demands or possessing valuable data.”
Infrastructural Targets
The vulnerability of state infrastructure was laid bare in May as state institutions and telecommunications networks bore the brunt of coordinated campaigns. Globally, governments and telecoms providers were the second and third most attacked sectors, averaging over 2,600 attacks a week per organization.
The fallout across the continent has been acute. Egyptian government and public-service web portals were hit by coordinated campaigns tied to geopolitical hacktivist groups. Meanwhile, in South Africa, a wave of breaches compromised critical state bodies, including the South African Revenue Service (SARS), the State Information Technology Agency (SITA), and the City of Ekurhuleni municipality. Security analysts note that the simultaneous targeting of telecom firms and state systems indicates a deliberate strategy to compromise interconnected national infrastructure.
The AI Double-Edged Sword
The rapid corporate adoption of generative artificial intelligence is inadvertently widening the digital flank for African enterprises. Check Point’s data shows that one out of every 25 GenAI prompts submitted from corporate networks in May carried a high risk of leaking sensitive enterprise data, impacting 91% of companies using the technology. The exposure is driven by volume; the average enterprise employee now generates roughly 70 prompts a month across nearly a dozen different AI applications.
Simultaneously, cybercriminals are leveraging AI tools to automate and accelerate their own operations using the technology to write flawless phishing emails, harvest credentials at scale, and rapidly exfiltrate data once inside a network. These AI-driven tactics are frequently paired with the exploitation of unpatched, known security flaws in perimeter systems like corporate VPNs and firewalls.
“The pace of adoption is increasingly outstripping governance and security controls,” de Bruin said. “AI is simultaneously driving productivity gains and expanding organizational risk.”
While Africa recorded a slight year-on-year dip in total raw attack volumes during May, data scientists warn against interpreting the pause as a sign of stabilizing security.
“May’s lower attack volumes should not be interpreted as a reduction in cyber risk,” said Omer Dembinsky, Data Research Manager at Check Point Research. “Attackers are continuously adapting, shifting their timing and techniques rather than slowing down.”
















