9 April 2025 • 3 min read

No business is safe: The rising threat of cyber extortion in South Africa

With the average cost of a data breach in South Africa reaching nearly R50 million, businesses are facing an aggressive wave of ransomware and sophisticated email compromise attacks. Experts emphasize that proactive defense, including dark web monitoring and employee training, is now essential to prevent catastrophic financial and reputational damage.

Ryan van de Coolwijk

Ryan van de Coolwijk

Ryan van de Coolwijk

No business is immune to the growing wave of cybercrime. In today’s hyper-connected world, cyberattacks pose a serious and escalating threat to companies of all sizes and across all industries. From startups to multinationals, organisations are increasingly being targeted by cybercriminals who leave behind financial devastation, reputational harm, and operational chaos.

Just last month, JSE-listed Astral Foods fell victim to a ransomware attack on its poultry division, resulting in an estimated R20 million profit loss. In a separate incident, real estate group Pam Golding suffered a data breach where hackers accessed sensitive customer information from its CRM system. These high-profile attacks highlight a dangerous trend that’s becoming all too common in South Africa’s business landscape.

According to market research, the average cost of a data breach in South Africa climbed to nearly R50 million in 2024. This staggering figure illustrates just how catastrophic the financial impact of a cyber incident can be. Even more concerning, one in every 15 organisations across Africa experienced a ransomware attempt every week during the first quarter of 2023 an alarming frequency that outpaces global averages.

Despite the severity of these incidents, many companies still underestimate the broader, long-term impact of a cyberattack. “Beyond the immediate financial loss such as IT recovery, extortion payments and system downtime the real damage can be far more profound,” says Ryan van de Coolwijk, Product Head: Cyber at iTOO Special Risks. “Businesses face the risk of losing client trust, missing future business opportunities, and even seeing competitors take advantage of the situation.”

Van de Coolwijk explains that today’s cyber extortion landscape has evolved. While ransomware attacks that encrypt data were once the primary concern, cybercriminals have adapted their approach. Increasingly, they’re stealing data and threatening to leak or sell it unless a ransom is paid. This data could include customer records, financial information, and intellectual property. The fear of reputational damage from such leaks can be even more crippling than data encryption.

Another major concern is business email compromise. Here, attackers gain access to company email systems to impersonate executives or trick staff into authorising fraudulent transactions. These attacks are often sophisticated, highly targeted, and difficult to detect before the damage is done. Fraudulent transfer scams are also on the rise, with cybercriminals using clever social engineering tactics to manipulate companies into transferring funds to bogus accounts.

“As cybercriminals evolve their tactics, so too must businesses evolve their defenses,” Van de Coolwijk warns. “It’s critical that organisations invest in strong cybersecurity frameworks, keep their systems up to date, train employees to spot suspicious activity, and take threat intelligence seriously.”

To stay ahead of emerging threats, iTOO has turned to advanced technology that monitors the dark web where much of this malicious activity begins. By scanning the dark web for stolen data, compromised credentials and early warnings of planned attacks, iTOO is able to alert clients to threats before they materialise.

“The ability to detect and act on early signs of cybercriminal activity is a game changer. It gives companies the opportunity to take preventive steps, protect their operations, and maintain client trust before becoming the next target,” says Van de Coolwijk.

In a digital era defined by constant threat, proactive cybersecurity is no longer optional, it’s essential.