Blog

When the phish landed: attacks on African organisations

Case studies and analyses of phishing, BEC, ransomware and social-engineering incidents across the continent — sourced from public reporting, with the lessons that matter.

Analysis2024

Anatomy of invoice fraud: how supplier payments get stolen, step by step

One fraudulent change — the bank account — inside an otherwise genuine invoice flow. The five-stage anatomy, and the single control that breaks it.

Payment fraud2024

Bank of Uganda (2024): when fraudulent transfers reach a central bank

Ugandan press and Reuters reported roughly UGX 62 billion fraudulently transferred from central-bank accounts. What was confirmed, and the lessons.

Analysis2024

Mobile money fraud: the social-engineering patterns behind the losses

Impersonation calls, reversal scams, corporate wallet abuse: the recurring patterns documented by GSMA and INTERPOL, and the controls that break them.

Analysis2024

SIM swap and account takeover: why your MFA choice matters more in Africa

When the phone number anchors financial life, SIM-swap fraud defeats SMS-based MFA. How the pattern works and which authentication choices resist it.

Analysis2024

The INTERPOL African Cyberthreat Assessment 2024, in plain language

Scams, phishing and BEC dominate what African police actually see, with ransomware growing fast. The report's key findings, readably summarised.

Analysis2024

The SilverTerrier playbook: how BEC groups really target finance teams

Harvest, study, hijack the thread, cash out: the documented BEC sequence — and what finance-team training must actually cover.

Analysis2024

Why phishing is moving to WhatsApp — and why email-only simulation misses it

Business conversation moved to messaging apps; attackers followed. The documented WhatsApp lures, and the blind spot in email-only programmes.

DDoS2023

Kenya, July 2023: the week a DDoS wave stress-tested a digital state

Anonymous Sudan claimed attacks on eCitizen and payment services. Mostly DDoS — yet the episode shows why layered human and technical resilience decides outcomes.

Ransomware2023

Naivas, 2023: ransomware reaches Kenya's largest supermarket chain

The Mallox group claimed data theft from Naivas; the retailer confirmed an attack and reassured customers on card data. A precedent for East African retail.

Account takeover2023

The Flutterwave incident (2023): what was reported, what was denied

Media reported unauthorized transfers; the company denied losing funds. Either way, the credential-hygiene lesson for African fintech stands.

BEC2022

Operation Delilah (2022): the arrest of a SilverTerrier BEC leader

Years of cooperation between INTERPOL, African police and private researchers ended with an alleged BEC kingpin arrested at Lagos airport.

Data extortion2022

Shoprite Group, 2022: extortion comes for Africa's largest retailer

RansomHouse claimed data theft affecting Shoprite money-transfer customers in three countries — data extortion without encryption, aimed at a pan-African brand.

Credential compromise2022

TransUnion South Africa, 2022: the password that opened a credit bureau

N4ughtySecTU claimed a massive breach; TransUnion said the entry point was an authorised client's misused credentials. One password, a national extortion crisis.

Ransomware2021

Transnet ransomware, July 2021: the week South Africa's ports went manual

A ransomware attack forced Transnet's container terminals offline and triggered a rare force majeure — a wake-up call for African critical infrastructure.

Insider risk2020

Absa, 2020: the data leak that came from inside the bank

An Absa employee unlawfully shared customer data with external parties. The bank's forceful legal response made this South Africa's defining insider-threat case.

Social engineering2020

Experian South Africa, 2020: the breach that needed no malware

A fraudster posing as a legitimate client obtained data on millions of South Africans — pure social engineering at national scale, and a textbook human-risk failure.

BEC2020

Operation Falcon (2020): the takedown that showed the industrial scale of BEC

INTERPOL, the Nigeria Police Force and Group-IB arrested members of the TMT gang, whose phishing had touched organisations in 150+ countries.

Insider risk2020

Postbank, 2020: when insiders copied the key to every card

Employees reportedly obtained Postbank's printed encryption master key, enabling fraud and forcing the replacement of millions of cards. Insider risk, at full cost.

Mobile money2020

Uganda, October 2020: the aggregator breach that froze mobile money

The compromise of aggregator Pegasus Technologies suspended MTN and Airtel mobile-money services and exposed the third-party risk at the heart of African fintech.

Extortion2019

City of Johannesburg, October 2019: when a metro took itself offline

Attackers breached South Africa's largest city and demanded bitcoin. Johannesburg shut down its e-services, refused to pay, and rebuilt — with lessons for every municipality.