Ransomware is malicious software that locks an organisation’s files or systems, usually by encrypting them, and demands payment to restore access. Many gangs also steal data first and threaten to publish it. Government agencies, utilities, hospitals, banks and private companies in Africa have all been hit. This guide explains how attacks happen and how to reduce the risk.
How a ransomware attack unfolds
- Initial access: attackers get in through a phishing email, stolen passwords, an unpatched internet-facing system, or exposed remote access such as RDP or a VPN without 2FA.
- Spreading: they move through the network, gain administrator rights and find valuable data and backups.
- Data theft: sensitive files are copied out to use as extra leverage.
- Encryption: files and servers are encrypted, often at night or over a weekend.
- Extortion: a ransom note demands payment, usually in cryptocurrency, with threats to leak data.
Why African organisations are targeted
- Rapid digitisation without matching security investment
- Shortage of cybersecurity professionals
- Older, unpatched systems and pirated software
- Limited backups or backups connected to the main network
- Attackers are opportunistic: they hit whatever is exposed and weak
Prevention: the essentials
1. Backups that survive an attack
Follow the 3-2-1 rule: three copies of data, on two types of storage, with one offline or immutable (cannot be changed or deleted). Test restoring from backups regularly. Good backups are the single most important defence.
2. Strong access controls
- Enforce two-factor authentication on email, VPNs and remote access; see 2FA explained
- Limit administrator accounts and use them only when necessary
- Remove accounts for departed staff promptly
3. Patch and update
Apply security updates quickly, especially to internet-facing systems such as firewalls, VPNs and email servers. Replace unsupported software.
4. Reduce exposure
Do not expose remote desktop directly to the internet. Close unused ports and services.
5. Train staff
Teach employees to spot phishing and report suspicious emails quickly. See How to Spot Phishing Scams.
6. Use endpoint protection and monitoring
Modern endpoint detection tools can spot and stop ransomware behaviour. Review security alerts.
Prepare an incident response plan
- Who leads the response, and how to reach them out of hours
- How to isolate infected systems quickly
- Contacts for IT support, a cybersecurity firm, lawyers, insurers and regulators
- How to communicate with staff and customers
- How to keep operating on paper or backup systems
If you are hit
- Isolate affected devices from the network; do not switch everything off without advice, as evidence may be lost
- Call in experts and your national CERT or cybercrime unit
- Preserve evidence, including the ransom note
- Assess backups and plan restoration
- Meet legal duties: data protection laws in many African countries require notifying the regulator, and sometimes affected people, of personal data breaches within set timeframes. See Data Protection Laws in Africa
Should you pay the ransom?
Law enforcement agencies generally advise against paying. Payment does not guarantee you will get working decryption keys or that stolen data will be deleted, and it funds further crime. In some circumstances, payments may also raise legal issues. Make the decision with legal and expert advice.
For broader protection, read our Cybersecurity in Africa guide.

