Stolen passwords are SA’s biggest ransomware risk in 2026

A new report shows South Africa ranks slowest for ransomware recovery speed. Here's what a ransomware attack actually costs SA businesses.

Contributed Content

ransomware attacks south africa
SA's ransomware encryption rate hit 63%, above the global average, with recovery costing R17m on average. Image generated with our TN:AI workflow for illustration purposes.

Sophos presented its State of Ransomware in South Africa 2026 report to a select group of media at Alto234 in Sandton on Friday, outlining how ransomware is affecting South African organisations and how those attacks are changing.

Sixty-three percent of attacks on South African organisations resulted in data being encrypted, up from 60% the year before. That compares with a global average of 56%, putting South Africa noticeably above the international figure.

State of Ransomware in South Africa

The report draws on responses from 135 IT and cybersecurity leaders at South African organisations that experienced ransomware over the previous 12 months. The full global survey covered 2,158 respondents across organisations employing between 100 and 5,000 people, all surveyed between January and March 2026.

The cost of ransomware attacks in SA

Ransomware is malicious software that locks or encrypts a victim’s data and demands payment to restore access. But the cost of an attack goes well beyond the ransom itself, since it is designed to affect business operations and even reputation.

For South African organisations, the average recovery bill, excluding any ransom paid, came to approximately R17 million. This includes downtime, staff time, device and network repair or replacement, and lost business.

It was down from R21 million in the 2025 report, which is something. But R17 million is still the kind of number that shuts down a mid-sized business or at the very least sets back a large business by months.

And recovery was not quick. Only 40% of South African organisations recovered within a week, the lowest rate of any country surveyed. That is a notable drop from 47% the year before.

A further 13% took between one and six months to get back to normal, though that figure improved from 19% in the 2025 report.

Why South African organisations are hit

It comes down to:

  • compromised credentials
  • lack of adequate protection
  • lack of cybersecurity capacity
  • exploited software vulnerabilities
  • exposed applications and/or devices

“Ransomware attacks frequently begin with an identity, device or security weakness that the organisation already knows exists,” says Pieter Nel, Regional Head SADC for Sophos in South Africa.

“Compromised credentials allow criminals to appear as legitimate users, while unpatched vulnerabilities and exposed systems provide additional routes into the business.”

1. Compromised credentials

The most common technical cause of ransomware attacks locally was compromised credentials, meaning stolen or leaked login details that criminals used to get in.

This accounted for 27% of incidents.

2. Exploited software vulnerabilities

Exploited software vulnerabilities followed at 25%, down slightly from 28% in the 2025 report. Malicious emails were responsible for 22%.

3. Exposed applications and/or devices

For attacks that did not originate through email or phishing, user devices were the most common entry point, at 43% of incidents.

Exposed applications and systems accounted for 38%, and firewalls for 13%.

4. Lack of adequate protection

The operational picture is, if anything, more concerning than the technical one.

A lack of adequate protection was identified as the most common operational root cause by 47% of South African respondents.

5. Lack of cybersecurity capacity

That is the highest proportion recorded in any country in the survey. A lack of people or cybersecurity capacity was cited by 43%, and 42% said attackers exploited a known security gap that the organisation had not closed.

Known. Not unknown. Known.

The identity problem is a big issue here

One finding in the 2026 report stands apart from the rest. Of the South African organisations surveyed, 85% confirmed that their ransomware incident was the same event as their most significant identity attack of the year.

Globally, that figure was 67%. South Africa sits 18 percentage points above the global average on this measure, the highest rate in the survey.

An identity attack, in plain terms, is when criminals compromise the credentials or access rights of legitimate users: stealing a password, hijacking an account, or abusing an authentication system to move inside a network as though they belong there.

When ransomware and identity attacks are the same event, it means the attacker got in through a person, not a system vulnerability.

“Addressing these risks requires strong identity controls, properly configured security technologies and enough skilled capacity to monitor and respond to threats,” Nel says.

Two important recommendations:

Sophos recommends that organisations implement identity threat detection and response (ITDR), a category of security tools that monitors for suspicious behaviour tied to user accounts and credentials.

The report also recommends enforcing multi-factor authentication (MFA) across all access points.

MFA requires a second form of verification beyond a password, such as a code sent to a phone, and makes stolen credentials significantly harder to use.

The ransom numbers

The median ransom demand made against South African organisations fell sharply, dropping 57% from R16 million in 2025 to R6.8 million in the period covered by this report.

The median ransom payment also fell, by 28%, from R7 million to just under R5 million.

South African organisations typically paid 71% of the original demand. That is the lowest proportion of any country surveyed with a sufficient sample size, though it is higher than the 64% recorded in the 2025 report.

The share of demands reaching $1 million or more dropped from 49% to 33%, which may partly explain why median payments fell. Fewer demands at the extreme end pull the midpoint down.

More backups, fewer ransom payments

There is genuinely better news on recovery.

Of the organisations whose data was encrypted, 99% were able to recover it, in line with the global average. The proportion using backups to do so increased from 35% in the 2025 report to 54% this year.

Backup-based recovery is preferable to ransom payment: it is typically faster, cheaper over time, and does not fund the criminal infrastructure behind the attack. Correspondingly, the percentage of organisations that paid a ransom and recovered their data fell from 71% in the 2025 report to 58%.

Data theft alongside encryption also declined. Information was stolen in 27% of attacks where data was encrypted, compared with 39% the year before.

“The increase in backup use and decline in ransom payments are positive developments,” Nel says. “Backups must, however, be properly protected, regularly tested and supported by a recovery plan that teams can follow under pressure. An organisation only discovers whether its recovery process works when it is tested or when a real incident occurs.”

Sophos recommends storing backups offline or in immutable formats, meaning formats that cannot be altered or deleted, and building them into a documented incident response plan that staff can actually follow when things go wrong.

What it does to the people inside

The 2026 report also looked at what ransomware incidents do to IT and cybersecurity teams at organisations where data was encrypted, and the picture is one most people in those roles will recognise.

Among those teams, 52% reported increased pressure from senior leaders after an incident. At the same time, 42% said their teams received greater recognition. Those two things coexist, and the gap between them is its own kind of pressure.

A further 39% experienced changes to team or organisational structure following an attack. Thirty-six percent reported greater anxiety or stress about future attacks. And 24% said the team’s leadership had been replaced.

That last figure deserves a moment. Nearly one in four cybersecurity teams lost their leadership after an attack. It is a finding that does not appear in the headline numbers, but it says something about how organisations respond when things go wrong, and about the human cost of a threat that most coverage reduces to rand figures.

What to fix first

Prioritise:

  • identity security
  • fix email security
  • endpoint protection
  • backup infrastructure

Sophos’s recommendations from the report prioritise identity security above all else, given the 85% overlap between ransomware and identity attacks in South Africa. That means implementing ITDR tools, enforcing MFA, and auditing credentials regularly, including credentials tied to automated systems and non-human accounts, which are frequently overlooked.

Email security is the second priority. Phishing and malicious email together account for more than a third of ransomware root causes locally. The report recommends advanced email filtering and the implementation of DMARC, DKIM, and SPF protocols, which are email authentication standards that make it harder for attackers to spoof legitimate senders.

Endpoint protection and backup infrastructure round out the recommendations. Frontier AI tools are accelerating the speed at which attackers can find and exploit vulnerabilities in software, which makes keeping systems patched and endpoints hardened more urgent than it was even two years ago.

Sources:
[1] Sophos. “The State of Ransomware 2026.” Sophos, July 2026.

Before you @ us:

No, AI did not “write this article.” Calm down. This piece was produced using our TN:AI newsroom workflow. The opinions and typos belong to a human who has algorithmic side quests. (Hi!) We even wrote an AI policy so nobody panics.

🧠 AI-assisted research + summarisation 📝 Human edited + fact-checked

Sharing is caring! 

Featured reads: