SA firms hit with R17m ransomware recovery costs as attacks worsen

Exploited vulnerabilities followed at 25%, while malicious emails accounted for 22% of attacks.


Nearly two-thirds of ransomware attacks against South African organisations resulted in data encryption over the past year, with victims spending an average of more than R17 million to recover, according to a new cybersecurity report.

Sophos’s State of Ransomware in South Africa 2026 report found that 63% of ransomware incidents led to data encryption, up from 60% in 2025 and higher than the global average of 56%.

Recovery cost

The average recovery cost exceeded R17 million, excluding ransom payments. While lower than the R21 million reported last year, the figure still reflects the significant impact of downtime, system restoration, device repairs, staff costs and lost business opportunities.

The report, based on responses from 135 South African IT and cybersecurity leaders whose organisations were hit by ransomware in the past 12 months, found compromised credentials were the leading cause of attacks, accounting for 27% of incidents.

Shortcomings

Exploited vulnerabilities followed at 25%, while malicious emails were responsible for 22% of attacks.

Operational shortcomings also continue to leave organisations exposed. Nearly half of respondents (47%) cited inadequate security protection as the primary operational cause of attacks, the highest level recorded among all countries surveyed.

A lack of cybersecurity skills or capacity was identified by 43% of respondents, while 42% said attackers had exploited a known security gap.

“These figures show the extent of the disruption ransomware continues to cause in South Africa,” said Pieter Nel, regional head of the Southern African Development Community (SADC) for Sophos South Africa.

Identity-based attacks

The report also found a strong link between ransomware and identity-based attacks. Some 85% of South African organisations said their ransomware incident was also their most significant identity attack of the year, well above the global average of 67%.

Despite the rise in encryption attacks, organisations are showing signs of improving their recovery capabilities. Almost all businesses whose data was encrypted (99%) recovered it, while the use of backups as a recovery method increased from 35% in 2025 to 54% this year.

Ransoms

At the same time, fewer organisations paid ransoms to regain access to their data. The proportion of victims that paid fell from 71% to 58%, while incidents involving data theft declined from 39% to 27%.

Ransom demands also dropped sharply, with the median demand falling from R16 million to R6.8 million. The median ransom payment decreased to just under R5 million.

Identity controls

However, recovery remains slow. Only 40% of South African organisations recovered from an attack within a week, the lowest rate among all countries surveyed and down from 47% last year.

“Ransomware attacks frequently begin with an identity, device or security weakness that the organisation already knows exists,” Nel said.

He added that stronger identity controls, multi-factor authentication, vulnerability management and tested backup systems remain critical to reducing the impact of ransomware attacks.

Read more on these topics

Cybercrime cybersecurity hacked hacking internet tech