Ransomware encrypts a business’s files and sells the key back to it. South Africa records more of it than any other country in Africa, and the reason is not that local businesses are careless but that they are connected, profitable and under-monitored. This guide explains how an attack actually unfolds over days rather than minutes, why paying is usually the worst available option, and what the backup architecture that survives it looks like.
What is ransomware?
Ransomware is malicious software that encrypts an organisation’s data and demands payment for the decryption key. The business keeps its files but loses all access to them, which is functionally the same as losing them.
Most operations now run a second lever alongside the encryption. Before locking anything, the attacker copies the data out and threatens to publish it. That is double extortion, and it defeats the traditional answer of restoring from backup: you can recover your operations, but the stolen customer records are still in someone else’s possession.
This changes what the incident is. Encryption alone is a business continuity problem. Data theft is a regulatory and reputational one, with POPIA obligations attached.
How bad is ransomware in South Africa?
South Africa recorded 17,849 ransomware detections in a single year, the highest number of any country in Africa, according to Interpol’s 2025 Africa Cyberthreat Assessment. Egypt, Morocco and South Africa together showed a notable concentration of ransomware-related data leaks.
The same assessment documented an estimated three billion US dollars in financial losses from cybercrime across Africa between 2019 and 2025, and found that two thirds of surveyed African member countries reported cyber-related crime as a medium-to-high share of all crime.
Why South Africa leads the continent comes down to target attractiveness. The economy is comparatively digitised, businesses hold data worth stealing, and cyber insurance and incident response capability are less mature than in Europe. Attackers are commercially rational. They go where the ratio of payout to effort is best.
For resellers and MSPs, that gap is also the opportunity: clients who would not fund backup projects two years ago now sign them quickly. Partners building that practice can apply to become an accredited partner and get the vendor accreditation behind it.
How a ransomware attack unfolds
An attack does not arrive and encrypt in the same moment. An operator typically spends days inside a network first, and those days are the entire opportunity to stop it.
Initial access. Usually a phished credential, an exposed remote desktop service, or an unpatched internet-facing device. Nothing exotic.
Establishing persistence. The attacker installs a way back in that survives a reboot and a password change.
Privilege escalation. They work toward domain administrator rights, because encrypting one laptop is not a business event and encrypting the file server is.
Reconnaissance and exfiltration. They map what exists, find the finance and customer data, and copy it out. This is often the noisiest stage and the one monitoring is most likely to catch.
Backup destruction. They locate and delete or encrypt the backups. Deliberately, first. An operator who leaves working backups intact has nothing to bargain with.
Encryption. Triggered out of hours, typically a Friday evening or the start of a public holiday weekend, to maximise the time before anyone notices.
Every stage before the last one is detectable. A business that only finds out at stage six had no visibility at stages one through five, which is a monitoring problem rather than a malware problem.
Should you pay the ransom?
Paying should be the last option, because it funds the next attack and buys a decryption tool rather than a resolution. Several things go wrong even when the payment works.
Decryptors supplied by attackers are frequently slow and imperfect, and large environments have restored faster from backup than from a purchased key. Payment also does not undo exfiltration: the data is already gone, and there is no enforceable mechanism to make anyone delete it.
Paying additionally marks the business as one that pays, which is information that circulates among affiliates. Repeat targeting of previous payers is well documented in the incident response field.
The real decision is made long before the ransom note. A business with tested, isolated backups has a recovery path and can decline. A business without them has no room to negotiate at all, which is precisely the position the attacker spent a week engineering.
BUILDING RANSOMWARE RESILIENCE FOR CLIENTS?
LOOPHOLD distributes the backup and recovery stack South African partners deploy against it.
See partner enablement
How to protect against ransomware
Effective defence works on the assumption that prevention will eventually fail, so recovery has to be engineered rather than hoped for. Layer these in order of return.
Immutable backups. Backups that cannot be altered or deleted for a defined retention period, even by an account with administrator rights. This directly defeats stage five. Products such as Arcserve UDP and Wasabi Hot Cloud Storage with object lock exist for exactly this reason. If your backup can be deleted by a compromised admin account, it is not a ransomware control.
Tested restores. A backup nobody has restored from is an assumption. Schedule real restore tests and time them, because knowing recovery takes eleven hours changes what you promise the board.
Multi-factor authentication on remote access and email, closing the most common initial access route.
Patching internet-facing systems on a defined cycle. VPN concentrators, firewalls and remote desktop gateways are the doors being tried.
Network segmentation so a compromised workstation cannot reach the file server directly.
Monitoring that covers the days between access and encryption. This is the difference between a contained incident and a company-wide event.
A rehearsed incident plan naming who decides, who calls the lawyer and who notifies the Regulator. Written before it is needed, because nobody drafts clearly at 23:00 on a Friday.
What South African law requires after an attack
Section 22 of POPIA requires the responsible party to notify the Information Regulator and the affected data subjects where personal information has been accessed or acquired by an unauthorised person. A double-extortion ransomware attack meets that threshold by definition, since the data was copied out.
The Information Regulator publishes a prescribed form for this notification, and its guidance states that failing to use the form may result in the notification being regarded as non-compliant. Notification to data subjects must carry enough detail for them to protect themselves, including the likely consequences and the recommended steps to mitigate them.
Plan for this before it happens. Legal and communications work runs in parallel with technical recovery, not after it, and a business improvising both at once does neither well.
Where ransomware fits in the wider picture
An encryption event is the outcome of other failures rather than a standalone threat, which is why defending it means fixing the things that precede it. The initial access is usually phishing or an unpatched edge device. The escalation is usually weak identity controls. The severity is usually determined by backup architecture decided years earlier.
Our guide to cyber security for South African businesses covers the layered model these controls belong to, and teams that want the technical grounding on the network side can start with SonicWall certification training.
Businesses that recover well are not the ones that were never targeted. They are the ones that decided in advance that prevention would fail.
WANT THE BACKUP STACK THAT SURVIVES IT?
Talk to LOOPHOLD about Arcserve, Wasabi and vendor accreditation for South African partners.
Start my partner enquiry




