E-Business
Africa: 2023 Cyberthreats Landscape, Next Year Predictions

By Yusuph Kileo
In recent years, of African countries are working hard to adopt 2030 African digital transformation agenda. Finance, education, agriculture, government, security, and manufacturing, are actively adopting digital technologies and transitioning their operations to online platforms.

As we advance in technology throughout the continent, nations need to remember, cybersecurity and personal data protection are fundamental principles in the implementation of the digital transformation project in order to minimise the challenges that come along with the technology.
The year 2023 was filled with countless cyberattacks across many countries — Some of these attacks targeted critical infrastructure, financial institutions, governments and other companies.
As African countries are now pushing for digital transformation and experiencing rapid economic development, cybersecurity remains a pressing concern for businesses across Africa.
Unfortunately, some of the African countries indicate inadequate security measures to fight off cybercrime, leaving them highly susceptible to cyberattacks — They have weak prevention mechanisms to combat cyber threats and poor intrusion detection systems, thereby placing sensitive transactions at significant risk.
There is an increase in the volume and sophistication of cyberattacks in financial institutions.
According to the 2023 Africa Financial Industry Barometer, 97% of surveyed leaders of financial institutions in Africa rank cybercrime and regulatory constraints on cybersecurity as the leading threat to the financial services industry alongside worsening economic conditions.
These massive cyberattacks in the region threatens the security of the growing economy and critical infrastructure.
MTN Nigeria, lost $53 million from its mobile money service which forces them to sue several banks in the Nigeria, financial institutions and e-citizen portal where halted by distributed denial of service attack in Kenya, South Africa there is an increase in backdoor and spyware attacks with an alarming 106,000 recorded attempts.
There are many similar cybersecurity incidents in other African countries and there is a need of urgent action to strengthen protection measures.
Failure to counter cyberthreats can have serious consequences for individuals, businesses and the socio-economic development of the continent.
Africa is not alone in this, In September alone other part of the world experience massive cyberattacks — To mention few notable cyberattacks; On September 6, the travel booking company Sabre experienced a serious ransomware attack where by 1.3 terabytes of data were stolen by Dunghill and just few days letter, on September 11th another ransomware attack on save the children lead to the loss of 6.8 terabyte of data and entertainment company MGM Resorts also suffered a cyberattack which was made public on X saying that the security incident severely impacted its business operations.
The following day on September 12, Hong Kong-based cryptocurrency exchange platform, CoinEx, saw the loss of US$70 million in cryptocurrency following a cyberattack launched against it.
In 2023, the most common cyberthreats in Africa includes Insider threats, Social Engineering, Software update supply chain attacks, Phishing attacks, Mobile malware, online shopping fraud, Ransomware, Man-in-the-middle (MitM) attack, Cryptojacking attacks, IoT botnet DDoS attacks and Malware attacks among others.
According to the year 2023 Positive technology report, the most targeted organizations with cyberattacks were those in the financial sector (18%), followed by telecommunications companies (13%), government agencies (12%), and organizations from the trade (12%) and industrial (10%) sectors.
The impact brought by these growing cyberattacks includes, Loss of customer/business, Loss of organisation critical data, Threat to organisation/National Security, Damage of goodwill and Reputation, Loss of Revenue — Economic Losses, Temporary or permanent closure, Lawsuits and arbitrations, Danger of terrorism, Time wastage and System down time — reduce productivity.
2024 cyberthreats prediction
Many report shows Africa being the most targeted region with cyberattacks, the year 2024 new techniques of cyberattacks will likely emerge, such as the increase in AI usage, hacktivism and targeting of smart home tech.
New botnets and rootkits will also likely appear, and hacker-for-hire services might increase, as will supply chain attacks, which might be provided as a service on cybercriminals’ underground forums.
According to Kaspersky, Advanced Persistent Threats (APT) is expected to expand surveillance efforts to include more smart home technology devices, such as smart home cameras and connected car systems.
This is particularly interesting for attackers because those devices are often uncontrolled, not updated or patched and subject to misconfigurations. This is also a concern because more people work from home nowadays, and their companies could be targeted via weak points in the home worker devices.
More hacktivism is expected affect many parts of Africa. Hacktivists will run Distributed Denial of Service attacks, increasingly use tools for Deepfakes and impersonation/disinformation. In addition, destructive and disruptive operations can be done. T
he use of wipers in several current political conflicts or the disruption of power in Ukraine are good examples of both types of operations.
Cybercriminals are also expected to develop new methods for automating cyberespionage. One method could be to automate the collection of information related to victims in every aspect of their online presence: social media, websites and more, as long as it relates to the victims’ identity.
State-sponsored cyberattack numbers also have the potential to surge, amid increasing geopolitical tensions. These attacks will likely threaten data theft or encryption, IT infrastructure destruction, long-term espionage, and cyber-sabotage.
The generative AI tools usage will increase, this will facilitate the mass production of spear phishing email content, which is often used as the initial vector of infection when targeting organizations. The messages written by the tools are more persuasive and well-written compared to the ones written by cybercriminals. It might also mimic the writing style of specific individuals.
The widespread use of technology, combined with insufficient cybersecurity measures, lack of right skillset, inadequate legislation in the field of information security, and a low level of public awareness concerning information security, creates favorable conditions for cybercriminals. Moreover, many African countries are facing economic constraints, making it difficult to allocate sufficient funds for cybersecurity.
African governments must develop, implement and regularly update national cybersecurity policies and strategies, involving a wide range of stakeholders in the process.
Establishing a dedicated national institution (Cybersecurity authority) to coordinate cybersecurity activities, respond to cyber incident, monitor threats and help organizations recover from major cyberattacks should be a top priority for governments.
Governments should work on creating and implementing legislation for the protection of personal data. This legislation should combat cybercrime, guarantee the protection of personal data, and maintain the digital security of citizens and organizations.
Regular cybersecurity awareness should be conducted. People should be educated on potential privacy risks when working in virtual environments.
Governments should identify critical information infrastructure, disruption of which could cause non-tolerable events at the level of industries and countries.
Collaboration between governments and industry peers is also recommended to enhance collective defense against cyberattacks and exchange best practices and thoughts.
Organisations should implement best practices in safeguarding personal and corporate data.
Organizations should have an up to date incident response plan that will help in case of cyberattack. The plan should contain steps to take, as well as a list of people and services to reach in case of emergency. This plan should be regularly tested by conducting attack simulations.
Network segmentation might limit an attacker’s exploration of compromised networks. Critical systems in particular should be totally isolated from the rest of the corporate network.
Establishing continuous vulnerability assessment and triage as a basement for effective vulnerability management process
Implementing strict access controls is highly recommended. The principle of least privilege should always be in use for any resource. Multifactor authentication should be deployed wherever possible.
Mr Yusuph Kileo is an award-winning Cyber security and Digital Forensics Expert
E-Business
HURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria

Human Rights Writers Association of Nigeria (HURIWA) has opposed a bill seeking to compel major global social media companies to establish physical offices in Nigeria.

The rights advocacy group urged the National Assembly to discard the proposed legislation, warning that it could become a tool for censorship and undermine citizens’ constitutional right to freedom of expression, despite being presented as a measure to strengthen Nigeria’s digital economy and improve corporate accountability.
The position was contained in a presentation submitted yesterday by Emmanuel Onwubiko, national coordinator, HURIWA, to the chairman of the Senate Committee on ICT and Cyber Security.
The bill, sponsored by Senator Ned Munir Nwoko, has already passed second reading in the Senate and is before the committee for further legislative consideration.
HURIWA said it carefully reviewed the proposed legislation and concluded that compelling global technology companies to establish offices in Nigeria was unnecessary and potentially counterproductive.
The organisation argued that while the firms generate substantial revenue from Nigeria’s vast digital market, they already engage Nigerians through existing structures, including paying eligible content creators, working with local technology professionals and participating in legal proceedings whenever required.
According to the group, appointing local representatives where necessary would adequately address concerns about engagement with regulators and users without forcing the companies to maintain physical offices.
It also dismissed claims that mandatory country offices would significantly improve consumer complaint resolution, technology transfer or employment generation.
HURIWA maintained that the platforms already have effective feedback mechanisms for resolving users’ complaints and routinely appear before Nigerian courts through their representatives whenever litigation arises.
The group, however, said its greatest concern was the potential for the proposed law to be used as an instrument for restricting freedom of expression.
It argued that establishing local offices could expose global social media companies to pressure from government authorities to remove online content considered critical of those in power.
According to the rights group, the presence of social media companies in Nigeria could become an avenue for authorities to pressure them into abandoning internationally recognised digital rights standards in favour of politically motivated content moderation.
It recalled previous attempts to regulate social media in Nigeria that generated widespread concerns over possible restrictions on free speech, stressing that any legislation affecting the digital space must contain clear safeguards against abuse.
The organisation warned that the proposed law should never become “a backdoor mechanism for government surveillance, arbitrary content removal or political censorship.
E-Business
Nigeria Leads Africa in Online Gambling Regulation – GCI

Nigeria has emerged as one of Africa’s most regulated online gambling markets, even as illegal operators continue to dominate the continent, according to a new report by Gaming Compliance International (GCI).

The report, the first comprehensive assessment of online gambling across all 54 African countries, showed that Africa’s online gambling Gross Gaming Revenue (GGR) reached $23 billion in 2025.
However, only $5.2 billion (23 per cent) was generated by licensed operators, while $17.8 billion (77 per cent) remained in the unregulated market.
In West Africa, total online gambling revenue rose to $4.8 billion in 2025 from $4.3 billion in 2024. Of the 2025 figure, regulated operators accounted for $1.5 billion (31 per cent), while $3.3 billion (69 per cent) flowed to unlicensed platforms, highlighting the region’s persistent enforcement challenges.
Nigeria stood out as the region’s strongest performer, recording the lowest unregulated market share at 56 per cent, compared with the West African average of 69 per cent and the African average of 77 per cent.
The study also found that online gambling participation across Africa increased from 198 million people (13 per cent of the population) in 2024 to 215 million (14 per cent) in 2025.
Despite this growth, GCI estimated that illegal operators deprived African governments of about $3.55 billion in tax revenue in 2025. The number of unlicensed gambling platforms targeting African consumers also rose to 4,129, up from 3,644 in 2024.
Commenting on the findings, Matt Holt, chief executive officer, GCI, said the report provides regulators with the first continent-wide benchmark for strengthening oversight and consumer protection.
Ismail Vali, president, GCI, urged governments to develop competitive and well-regulated markets that encourage consumers to patronise licensed operators, boost public revenue and attract greater investment.
Online gambling in Nigeria is regulated by the Nation Lottery Regulatory Commission.
E-Business
Kaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators

At the height of the Northern Hemisphere tourist season, demand for communications and mobile Internet services rises sharply. Kaspersky’s security experts have uncovered scams that target anyone purchasing mobile connections or SIM cards worldwide.

Fraudsters create counterfeit websites that look like the portals of major regional and international telecom providers to trick users into revealing their phone numbers, personal details or banking information.
Kaspersky is sharing several examples of these fake login pages that mimic legitimate telecom operator sites and giving recommendations on how not to be deceived.
In the first case, scammers exploit the brand name of an international telecommunications company operating services in Asia, Africa and Europe. Fake authentication pages encourage users to put in their phone number and credentials.
While the first example shows the different design, the second scam site closely mimics the original log in page, making it hard for users to tell the difference and spot a fake. Entering authentication or payment data on fraudulent web sites may result in money or data loss and become a reason for more frequent spam and fraudulent calls.
Another example is a scam page which poses as another international communications company, working in North Africa, the Middle East and Southeast Asia. In this scheme scammers encourage users to top up their mobile data/Internet plans by entering their personal information and bank cards details.
Kaspersky experts have also identified a scam when cyber criminals suggest users enter their personal data to check and pay a bill inquiry. Such scam schemes are usually aimed at gaining victims’ personal data for further fraud or account hacking and stealing money.
“Because of the active use of AI, scammers can now create fake pages with ever increasing accuracy and speed, targeting the most popular user interest areas. We constantly see scams revolving around sports events, music concerts, seasonal sales and holidays. Unfortunately, the telecoms industry is no exception.
To keep your data and money safe, be vigilant when purchasing mobile or Internet plans online. Using an eSIM – purchased through an official app – is one way to avoid fake telecom sites, as it eliminates the need to enter personal details on questionable web pages.
If you’re unsure about a site’s legitimacy, search for the brand name directly in a search engine and enable a security solution that blocks phishing links for you,” comments Tatyana Kulikova, cybersecurity expert at Kaspersky.
E-Business3 days agoKaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators
General News3 days agoThree Entrepreneurs Secure ₦5 Million at The Gathering on 100 Pitchathon
Telecom2 days agoGSMA Supports Abuja Declaration on Meaningful Connectivity for Africa, Joins Partners to Launch ATLAS Umoja
News3 days agoAfrican Judges Pledge Support for AfCFTA’s Success
E-Financial3 days agoChatPay Unveils Public Waitlist for WhatsApp-Based Banking Platform
Telecom2 days agoMTN Nigeria Warns Customers Against Fake ‘One Month Free Data’ Promotion
Telecom3 days agoAirtel Africa Backs London Listing
News2 days agoNigeria, Israel Strengthen Research, Technology Collaboration

















