Ransomware hits SA services hard, recovery bills top R17m

Ransomware hits SA services hard, recovery bills top R17m

Ransomware hit most SA organisations, costing over R17 million to recover

Ransomware encrypted data in nearly two-thirds of attacks on South African organisations over the past year, and victims spent an average of more than R17 million to recover. Those figures, drawn from Sophos’s State of Ransomware in South Africa 2026 report, point to a disruption that reaches well beyond IT departments: when systems go down, services stall, work stops and opportunities are lost.

The report surveyed 135 South African IT and cybersecurity leaders whose organisations were hit by ransomware in the past 12 months. It found that 63% of incidents led to data encryption, up from 60% in 2025 and above the global average of 56%.

The average recovery cost exceeded R17 million, a figure that excludes ransom payments. While lower than the R21 million reported last year, it still reflects the weight of downtime, system restoration, device repairs, staff costs and lost business opportunities. For the public, the concern is what that downtime means in practice: interrupted operations at organisations people rely on every day.

How attackers get in is a story of familiar weaknesses. Compromised credentials were the leading cause, accounting for 27% of incidents. Exploited vulnerabilities followed at 25%, while malicious emails were responsible for 22% of attacks.

Operational shortcomings continue to leave organisations exposed. Nearly half of respondents, 47%, cited inadequate security protection as the primary operational cause of attacks, the highest level recorded among all countries surveyed. A lack of cybersecurity skills or capacity was identified by 43% of respondents, while 42% said attackers had exploited a known security gap. The report also found a strong link between ransomware and identity-based attacks: 85% of South African organisations said their ransomware incident was also their most significant identity attack of the year, well above the global average of 67%.

“These figures show the extent of the disruption ransomware continues to cause in South Africa,” said Pieter Nel, regional head of the Southern African Development Community (SADC) for Sophos South Africa.

Meanwhile, there are signs of resilience. Almost all businesses whose data was encrypted, 99%, recovered it, while the use of backups as a recovery method increased from 35% in 2025 to 54% this year. Fewer organisations paid ransoms to regain access, with the proportion of victims that paid falling from 71% to 58%, and incidents involving data theft declining from 39% to 27%. Ransom demands also dropped sharply: the median demand fell from R16 million to R6.8 million, and the median ransom payment decreased to just under R5 million. Further detail on the report is available at https://www.citizen.co.za/lifestyle/technology/sa-firms-hit-with-r17m-ransomware-recovery-costs-attacks-worsen/

Recovery, however, remains slow. Only 40% of South African organisations recovered from an attack within a week, the lowest rate among all countries surveyed and down from 47% last year.

“Ransomware attacks frequently begin with an identity, device or security weakness that the organisation already knows exists,” Nel said. Stronger identity controls, multi-factor authentication, vulnerability management and tested backup systems remain critical, he added, to reducing the impact of ransomware attacks. For organisations and the citizens they serve, closing known gaps before attackers find them may be the most practical protection available.

Q&A

How many South African organisations were surveyed and what share of attacks encrypted data?

The Sophos report surveyed 135 South African IT and cybersecurity leaders whose organisations were hit by ransomware in the past 12 months, and 63% of incidents led to data encryption, up from 60% in 2025 and above the global average of 56%.

What were the main ways attackers got into organisations?

Compromised credentials were the leading cause at 27% of incidents, exploited vulnerabilities followed at 25%, and malicious emails were responsible for 22% of attacks.

What operational shortcomings left organisations exposed?

Nearly half of respondents, 47%, cited inadequate security protection as the primary operational cause of attacks, the highest level recorded among all countries surveyed. A lack of cybersecurity skills or capacity was identified by 43%, and 42% said attackers had exploited a known security gap.

What signs of resilience did the report find?

Almost all businesses whose data was encrypted, 99%, recovered it. Backup use as a recovery method rose from 35% in 2025 to 54% this year, the proportion of victims paying ransoms fell from 71% to 58%, data theft incidents declined from 39% to 27%, and the median ransom demand dropped from R16 million to R6.8 million.