SA Orgs Face Faster, Coordinated Ransomware Attacks
South African organizations face a growing threat from ransomware, and the numbers tell a troubling story. Attackers are moving faster, coordinating better, and demanding higher payouts than ever before. New data shows a dramatic reduction in the time threat actors spend inside networks before detection, and that speed is forcing a fundamental rethink of how businesses approach cybersecurity.

Attackers Are Moving Faster Than Ever

The numbers here are stark. Average attacker dwell time, the period between initial access and detection, dropped from 117 days in 2024 to just 18 days in 2025. That’s according to the 2025 Cyber Incident Statistics and Comparative Analysis from cybersecurity firm Cyanre.

In some cases, attackers completed their entire operation within a single day of gaining access. Speaking to ITWeb, Lukas van der Merwe, associate director at Cyanre, called this acceleration part of a broader shift in how cybercrime operates.

Why Attacks Are Getting Faster

Van der Merwe attributes this speed to what he calls the increasing industrialisation of cyber crime. Ransomware-as-a-service platforms, specialized criminal ecosystems, and automated tools have made attacks scalable in a way they weren’t before. Artificial intelligence adds another layer, allowing threat actors to identify and exploit vulnerabilities more efficiently than manual methods ever could.

The shift goes beyond tools though. Attackers now operate like structured businesses with a different core objective. Data has replaced systems as the primary asset under threat, Van der Merwe explained. The goal isn’t disruption anymore. It’s acquiring data, controlling it, and using it as leverage.

Why South Africa Is a Target

South Africa presents an unusually attractive combination for attackers: valuable data paired with inconsistent defenses. The country has a relatively mature digital economy, but cyber resilience across organizations varies wildly.

A few factors compound the risk:

  • Skills shortages in cybersecurity teams
  • Legacy infrastructure still running in many organizations
  • Inconsistent security maturity across sectors
  • Weak monitoring systems that delay detection

Attackers exploit this unevenness. They scan for vulnerable systems opportunistically or simply buy access from criminal marketplaces when it’s available.

Ransom Payments Are Climbing

Cyanre’s incident response data shows a clear upward trend in payment rates. In 2025, 30% of their 15 facilitated threat actor engagements ended in payment. By the first seven months of 2026, that number jumped to 46%, with 6 out of 13 engagements resulting in payment.

Sophos’s annual State of Ransomware in South Africa research backs this up. Their data shows 43% of surveyed South African organizations paid ransoms in 2024. That figure jumped to 71% in 2025, with most payments made through cryptocurrency like Bitcoin.

Resilience Matters More Than Prevention Alone

These findings point to a necessary shift in strategy. Organizations can no longer operate on the assumption that prevention alone will keep them safe. Given how widely available stolen credentials and criminal tools have become, breach should be treated as a matter of when, not if.

Cyber resilience means an organization can keep critical operations running even during a crisis. Prepared organisations have already considered who makes decisions, how incidents are escalated, how stakeholders communicate, Van der Merwe said. These decisions need to be rehearsed well before an attack happens, not figured out in the middle of one.

The Hashlytics Take

What stands out here isn’t just the speed of these attacks. It’s the maturity of the criminal ecosystem behind them. When ransomware operates with the efficiency of a SaaS business, traditional security postures built around slow, methodical defense simply can’t keep pace. For South African organizations still relying on legacy systems and reactive monitoring, the 18-day dwell time isn’t a warning. It’s already too late by the time most teams notice.

Follow Hashlytics on Bluesky, Facebook, LinkedIn, Telegram and X to Get Instant Updates