Connect with us

E-Business

SophosLabs Research Reveals Africa’s Cyber Threats Level

Published

on

sophos new.jpg
Kindly share this post

Sophos, a global leader in network and endpoint security (www.sophos.com/en-us/lp/endpoint5reasons.aspx?cmp=701j0000001q1B9AAI), has revealed SophosLabs research that indicates a growing trend among cybercriminals to target and even filter out specific countries when designing ransomware and other malicious cyberattacks.

From the research result, African countries where shown to be on average threat level.

The African countries that were at an average level, according to SophosLabs include: Tanzania – 11.1 percent Kenya – 11.5 percent South Africa – 11.6 percent Egypt – 12.4 percent Angola – 15.7 percent Nigeria – 15.7 percent Tunisia – 16.4 percent Morocco – 16.6 percent Uganda – 24.9 percent Ghana – 25.5 percent Mozambique – 28.3 percent Algeria – 30.7 percent Zambia – 35.5 percent and Malawi – 39.4 percent.

The research includes information from millions of endpoints worldwide and is analyzed by the team at SophosLabs.

To lure more victims with their attacks, cybercriminals are now crafting customized spam to carry threats using regional vernacular, brands and payment methods for better cultural compatibility, according to Sophos.

Advertisement

Ransomware cleverly disguised as authentic email notifications, complete with counterfeit local logos, is more believable, highly clickable and therefore more financially rewarding to the criminal.

To be as effective as possible, these scam emails now impersonate local postal companies, tax and law enforcement agencies and utility firms, including phony shipping notices, refunds, speeding tickets and electricity bills.

SophosLabs has seen a rise in spam where the grammar is more often properly written and perfectly punctuated.

“You have to look harder to spot fake emails from real ones,” said Chester Wisniewski, senior security advisor at Sophos. “Being aware of the tactics used in your region is becoming an important aspect of security.”

Researchers also saw historic trends of different ransomware strains that targeted specific locations. Versions of CryptoWall predominantly hit victims in the U.S., U.K., Canada, Australia, Germany and France, TorrentLocker attacked primarily the U.K., Italy, Australia and Spain and TeslaCrypt honed in on the U.K., U.S., Canada, Singapore and Thailand.

Advertisement

The analysis also shows Threat Exposure Rates (TER) for countries during the first three months of 2016.

Although Western economies are more highly targeted, they typically have a lower TER. Nations ranked with the lowest TER include France at 5.2 percent, Canada at 4.6 percent, Australia at 4.1 percent, the U.S. at 3 percent, and the U.K. at 2.8 percent..

The African countries were reported to be at an average level.

Algeria at 30.7 percent, Bolivia at 20.3 percent, Pakistan at 19.9 percent, China at 18.5 percent and India at 16.9 percent are among countries with the highest percentage of endpoints exposed to a malware attack

“Even money laundering is localized to be more lucrative. Credit card processing can be risky for criminals, so they started using anonymous Internet payment methods to extort money from ransomware victims,” said Wisniewski. “We have seen cybercrooks using local online cash-equivalent cards and purchasing locations, such as prepaid Green Dot MoneyPak cards from Walgreens in the U.S. and Ukash, which is now paysafecard, from various retail outlets in the U.K.”

Advertisement

Tweet This: “Designer” cyber threats on the rise with localized logos, language and payment methods, according to Sophos.

The concept of filtering out specific countries has also emerged as a trend.

“Cybercriminals are programming attacks to avoid certain countries or keyboards with a particular language,” said Wisniewski. “This could be happening for many reasons. Maybe the crooks don’t want attacks anywhere near their launch point to better avoid detection. It could be national pride or perhaps there’s a conspiratorial undertone to create suspicion about a country by omitting it from an attack.”

Banking is an example of how cybercriminals are using location-based malware to be more prosperous. Sophos research reveals historically how Trojans and malware used to infiltrate banks and financial institutions converges on specific regions: Brazilian banker Trojans and variants pinpoint Brazil; Dridex is predominant in the U.S. and Germany; Trustezeb is most prevalent in German speaking counties; Yebot is popular in Hong Kong and Japan.

Zbot is wider spread, but mostly in the U.S., U.K., Canada, Germany, Australia, Italy, Spain and Japan.

Advertisement

“There is an entire cottage industry of uniquely-crafted Trojans just targeting banks in Brazil,” said Wisniewski.

With cybercriminals having a deliberate hand in creating threats that look authentic and are specifically targeted, it is more difficult to recognize malicious spam.

Home computer users are often a target of these attacks and should protect their systems from sophisticated malware threats. Free enterprise-grade security software that can detect threats and protect both Mac and PC for the home user is available from Sophos Home.

This research and analysis is from SophosLabs, a network of security experts across the world who detect and track all types of Internet breaches 24/7/365 worldwide, including computer viruses, advanced malware and Trojans, spam, web threats, hack attacks and more.

SophosLabs receives and investigates millions of emails, URLs, files and other data points daily and leverages its extensive expertise within the group to develop new definitions that detect entire classes of threats and new variants.

Advertisement

With facilities strategically located in Australia, Hungary, U.K. and Canada, SophosLabs experts also monitor and determine threat trends and maintain malware, spam and web threat dashboards in real time.

More than 100 million users in 150 countries rely on Sophos’ complete security solutions as the best protection against complex threats and data loss.

Simple to deploy, manage, and use, Sophos’ award-winning encryption, endpoint security, web, email, mobile and network security solutions are backed by SophosLabs – a global network of threat intelligence centers.

Sophos is headquartered in Oxford, U.K., and is publicly traded on the London Stock Exchange under the symbol “SOPH.” More information is available at www.sophos.com.

*Sample of a Phishing mail intercepted by Nigeria CommunicationsWeek reporter on Monday, May 9, 2016. Google has since denied been the source of such email.

Advertisement

 

 

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals

Published

on

Kindly share this post

At its recent Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region Kaspersky shared the results of a global study conducted by its internal research center which surveyed 1,800 IT and cybersecurity decision-makers and specialists from organisations across 18 countries and multiple industries.

The report shows that the pace of AI integration across organisations is rapid, despite associated risks. The company’s experts stressed that while AI adoption delivers clear efficiency gains, it must be accompanied by robust cybersecurity solutions, well-defined internal procedures, and comprehensive employee education programmes.

The report highlights a clear organisational preference for AI-enhanced technology: 68% of respondents said they would recommend a solution with AI features built in, while a mere 5% indicated they would prefer to avoid AI-enabled tools. This overwhelming endorsement underscores how deeply AI has embedded itself as a value driver across the modern enterprise.

AI has become a mainstream productivity tool spanning many business functions. The global survey findings confirm that employees across departments are already relying on AI tools for a wide range of everyday tasks, including: data analysis & visualisation (54%), project management (49%), search for information (47%), department-specific tasks (46%), text generation and editing (41%).

While organisations recognise the tangible benefits AI tools bring – including improved process efficiency and enhanced quality of deliverables – they also see the associated dangers. 82% of respondents voiced concerns about the risks AI poses to their organisation. These concerns are grounded in real-world experience.

Advertisement

Among the 87% of organisations worldwide that faced a cyber incident in the past year, 13% reported that they had experienced threats stemming specifically from AI-related vulnerabilities.

Notably, 74% of respondents believe that these risks can be effectively mitigated through employees’ responsible behaviour — pointing to the critical importance of security awareness and training in the AI era.

“The speed at which organisations are embracing AI is remarkable, but it must be matched with an equally strong commitment to security. We are already seeing a growing range of threats directly tied to AI adoption – whether it’s malware camouflaged as popular AI tools, vulnerabilities introduced through unsecure vibecoding, or leaked access credentials to corporate AI platforms and malicious skills by AI agents.

Managing these risks requires a holistic approach: the right technology, well-defined procedures, and a security-aware workforce,” comments Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

E-Business

How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

Published

on

Kindly share this post

Malagasy Vanilla has transformed its decades-old wholesale business by embracing direct-to-consumer sales through Temu, enabling the family-run company to reach customers in 14 European markets while significantly reducing logistics costs.

How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

For years, premium Madagascan vanilla supplier Malagasy Vanilla sold exclusively to restaurants, bakeries and wholesalers because the cost of shipping a single pack to individual customers often equalled the value of the product itself. That changed after the company joined Temu’s Local Seller Program in November 2025.

The Belgian-based business, which sources high-quality vanilla from Madagascar, has leveraged Temu’s logistics network to cut domestic shipping costs by nearly half through a partnership with Belgian postal operator Bnode. The move has enabled the company to enter the retail market for the first time and quadruple its sales within four months.

According to Belinda Rabenandrasana, co-Chief Executive Officer of Malagasy Vanilla, Temu has opened up an entirely new customer segment for the company.

“Temu opened a new avenue for us,” she said. “We were finally able to explore selling to individuals.”

Advertisement

The platform now contributes between five and 10 per cent of the company’s overall revenue.

Expansion into 14 European Markets

Malagasy Vanilla is among businesses participating in Temu’s Local Seller Program, launched in Europe in 2024 to help local merchants expand beyond their domestic markets.

Through partnerships with more than 150 logistics providers across Europe—including Bnode in Belgium, La Poste in France and DHL Group in Germany—Temu offers sellers access to affordable shipping and delivery infrastructure without requiring major investment in logistics.

After successfully establishing direct-to-consumer sales in Belgium, Malagasy Vanilla expanded into 14 European countries, including Germany, France, Spain and Poland.

Rabenandrasana said the logistics support, competitive shipping rates and seller assistance provided by Temu made the expansion possible.

Advertisement

“Without Temu and its partnership with Bnode, it would have been very difficult for a small business like ours to start selling directly to consumers,” she said.

She added that Temu also assists sellers in managing regulatory requirements such as the European Union’s Extended Producer Responsibility (EPR) compliance, making cross-border operations easier for small businesses.

Three Generations of Vanilla Expertise

Malagasy Vanilla traces its roots to three generations of the Rabenandrasana family in Madagascar’s vanilla industry.

Belinda’s grandfather began trading vanilla locally, while her father expanded operations across Madagascar. She launched the company’s international business in 2017, supplying premium Madagascan vanilla to European restaurants, pastry shops and food wholesalers before establishing operations in Belgium in 2023.

The company partners with growers and producer associations in Madagascar, where between 20 and 40 workers oversee the six- to 10-month curing process that transforms green vanilla pods into premium black vanilla.

Advertisement

Operations in Belgium focus on packaging, quality assurance and distribution.

Customer Reviews Drive Growth

Under its Lavani brand, Malagasy Vanilla sells gourmet-grade whole vanilla pods targeted at both professional chefs and home baking enthusiasts.

Rather than relying heavily on paid advertising, the company has benefited from Temu’s product discovery tools and customer reviews, helping the niche brand gain visibility organically.

According to Rabenandrasana, strong customer feedback has played a significant role in increasing traffic and boosting sales.

The brand currently maintains a customer review rating exceeding 99 per cent on the platform.

Advertisement

Future Plans

Looking ahead, Malagasy Vanilla plans to expand its European footprint further by establishing a warehouse in France and increasing sales across the continent.

The company is also developing new products, including vanilla extract and vanilla sugar, while planning to open a physical retail and production facility in Belgium later this year.

In addition, it intends to launch a social-impact initiative aimed at supporting vanilla-growing communities in Madagascar.

Reflecting on the company’s evolution, Rabenandrasana said the business continues to build on her family’s legacy.

“My grandfather worked locally, my father expanded nationally, and now we are building internationally,” she said.

Advertisement

Kindly share this post
Continue Reading

E-Business

FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

Published

on

Kindly share this post

Stakeholders in Nigeria’s digital economy have urged the Federal Government to review its partnership with global recruitment platform Hello.cv under the 3 Million Technical Talent (3MTT) programme, citing concerns over data security, digital sovereignty and the country’s “Nigeria First” policy.

FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

3MTT

The concerns follow the Federal Ministry of Communications, Innovation and Digital Economy’s announcement on May 6 of a 10 million-dollar partnership with Hello.cv aimed at increasing the global visibility of Nigerian technology professionals.

Under the initiative, 20,000 selected 3MTT fellows will receive a global professional profile package, including an Artificial Intelligence (AI)-powered job search agent, a professional curriculum vitae (CV) writer and a personal .cv domain, valued at 500 dollars per participant.

While stakeholders acknowledged the programme’s potential to improve global employment opportunities for Nigerian tech talent, they expressed concerns about the implications of hosting participants’ digital identities and data on a foreign domain.

Chief Executive Officer of Cyberchain and Global Digital Economy Strategist, Engr. Jude Ozinegbe, said the arrangement raised important questions about data ownership and jurisdiction.

According to him, registering domains under an entity outside Nigeria gives that entity a degree of control over activities associated with the domain.

Advertisement

“When you register your domain under a different entity outside your jurisdiction, that entity will have access to whatever is happening within that domain.

“In the long run, the Nigeria Data Protection Commission (NDPC) may have to examine the agreement and assess the security implications of such domain ownership,” he said.

Ozinegbe urged the NDPC to review the security protocols employed by Hello.cv to ensure compliance with Nigeria’s data protection regulations.

Also speaking, Ugonma Egwuatu of ECAM Global Services, an information and communications technology and data protection firm, said the security of data belonging to 20,000 fellows should be of significant interest to regulators.

She noted that while the ministry had the authority to determine how the programme was implemented, there was a need for greater transparency regarding the handling of participants’ personal information.

Advertisement

“The NDPC requires its registered Data Protection Compliance Organisations (DPCOs) to subscribe to the .ng domain.

“If a government ministry permits trainees to operate on a foreign domain, then the commission should examine the arrangement because we are dealing with the data of 20,000 Nigerians,” she said.

Egwuatu also called for clarity on how data generated through the platform would be processed, stored and protected.

“There should be explanations regarding the backend. What are they doing with the data of people who visit these sites? Why use a foreign domain instead of the .ng domain? These are legitimate questions that deserve answers,” she said.

She added that government should ensure appropriate third-party agreements and safeguards were in place before implementing such initiatives.

Advertisement

On his part, Chief Executive Officer of DNS Africa, Dr. Adebunmi Adeola Akinbo, said the objectives of the programme could still have been achieved while leveraging Nigeria’s country code top-level domain.

According to him, Hello.cv could have registered a hello.cv.ng or hellocv.ng domain in collaboration with the Nigeria Internet Registration Association (NiRA).

“The .ng domain can conveniently accommodate such a platform. If Hello.cv intends to onboard millions of Nigerians, it can work with NiRA to create a local domain structure.

“That way, the investment remains within Nigeria, strengthens the digital economy and supports local internet infrastructure,” he said.

Akinbo argued that excluding the .ng domain from the initiative undermined Nigeria’s digital identity and sovereignty.

Advertisement

“As good as the programme may sound, leaving the .ng domain outside this engagement and taking Nigerian data outside the country’s digital jurisdiction is not the best approach,” he said.

Also commenting, Founder and Chief Executive Officer of Precise Financial Systems Ltd., Yele Okeremi, stressed the importance of ensuring that investments in Nigeria’s digital economy create long-term domestic value.

According to him, building a sustainable technology ecosystem requires more than developing skilled professionals.

“Investment, particularly in technology and the knowledge economy, is not just about having smart people.

“It is also about who owns the infrastructure and who ultimately benefits from the value created. Nigeria must ensure it retains as much of that value as possible,” he said.

Advertisement

Similarly, Chief Executive Officer of the Internet Exchange Point of Nigeria (IXPN), Muhammed Rudman, described the use of foreign domains for a government-sponsored initiative as inconsistent with efforts to promote Nigeria’s digital economy.

“I don’t know where this idea came from, but it is unpatriotic for Nigerian companies funded by Nigerian resources to adopt .cv domains instead of .ng.

“Global companies such as Google register country-specific domains like google.ng when operating locally. Registering 20,000 additional .ng domains would improve Nigeria’s online visibility and strengthen the local internet ecosystem,” he said.

Rudman urged the Federal Government to support indigenous digital infrastructure by encouraging the use of the .ng domain.

The 3 Million Technical Talent (3MTT) programme is a flagship initiative of the Federal Ministry of Communications, Innovation and Digital Economy aimed at equipping Nigerians with globally relevant digital skills.

Advertisement

The programme provides free training in areas including software development, artificial intelligence, cloud computing, cybersecurity, data analytics, machine learning, animation, DevOps and user interface/user experience design through a hybrid learning model.

Stakeholders maintained that while the partnership with Hello.cv could expand international employment opportunities for Nigerian technology professionals, greater attention should be paid to safeguarding the country’s digital assets, promoting local internet infrastructure and ensuring compliance with Nigeria’s data protection framework.

Kindly share this post
Continue Reading

Trending