Threat Intelligence Trends in South Africa

5 Minute read
Seyton Hayes
Technical Director | Digital Forensics & Incident Response Specialist
Threat Intelligence Trends in South Africa
In this article

Share this article

Threat intelligence only earns its name when it changes decisions. The patterns below are the ones our managed detection and response team is seeing most often across South African client environments — and they are the ones most worth feeding into detection content, tabletop scenarios, and board reporting this quarter.

The short answer

Five threat patterns are dominant in South African environments this year: ransomware affiliate operations targeting mid-market and enterprise, business email compromise tied to executive impersonation, mobile money and banking fraud, identity-led intrusions via stolen credentials, and supply chain compromise through third-party SaaS. Each maps to specific MITRE ATT&CK techniques.

Ransomware affiliates — operators below the headlines

Ransomware-as-a-service has decoupled the operators that develop the encryptor from the affiliates that gain initial access and execute. The implication for defenders: the named brand groups are interchangeable; the affiliate tradecraft is more stable. Detection focuses on the consistent affiliate techniques — credential abuse, BloodHound and ADRecon reconnaissance, RDP and VPN abuse, and double-extortion data staging.

Business email compromise — still the highest-frequency loss event

BEC remains the most frequently reported loss event by South African organisations to insurers and SABRIC. Executive impersonation, supplier invoice redirection, and payroll diversion are the recurring scenarios. The control set is well understood — DMARC enforcement, mailbox rule monitoring, out-of-band payment verification, callback procedures on changes — but adoption is uneven. AI-generated content has raised the quality of social engineering lures.

Mobile-money and banking fraud — uniquely African pressure

The continent’s mobile-money penetration and the maturity of South African banking digital channels produce a fraud landscape that does not map neatly to global threat reports. SIM swap, vishing, and in-application abuse persist alongside SS7 attacks against MFA via SMS. The defensive answer is identity hardening on the customer side and transaction monitoring on the institution side.

Identity-led intrusion — the credential is still the front door

Most intrusions in our caseload begin with a credential: stolen, credential-stuffed, password-sprayed, or phished. Once inside, attackers move laterally through identity infrastructure — Kerberoasting, AS-REP roasting, golden ticket creation, abuse of conditional-access misconfigurations. Detection coverage against ATT&CK Discovery and Lateral Movement techniques produces the biggest improvement in mean time to detect.

Supply-chain compromise via SaaS — the new flank

As organisations push more workloads to SaaS, third-party identity providers, ticketing systems, code repositories, and finance platforms become attractive intermediate targets. Compromising a SaaS vendor’s OAuth tokens or API keys across many customer tenants is now a documented pattern. Third-party risk management programmes that monitor SaaS posture continuously close this gap; questionnaire-based reviews do not.

These threat patterns increasingly affect operational continuity, fraud exposure, cyber insurance reviews, and executive reporting — not just security tooling decisions.

AI-assisted social engineering and reconnaissance

Generative AI has lowered the effort required to run convincing social-engineering campaigns at scale. Phishing emails are now better written, more context-aware, and increasingly personalised using publicly available organisational and executive information gathered during reconnaissance. Multilingual lures that previously exposed attackers’ mistakes are becoming harder for employees to identify, particularly in environments that operate across English and multiple regional languages.

AI-assisted reconnaissance is also accelerating how attackers profile organisations before targeting them. Public LinkedIn activity, supplier relationships, executive structures, procurement notices, breached credential databases, and exposed cloud services can now be aggregated and analysed far faster than traditional manual profiling allowed. The result is more convincing impersonation attempts and better-targeted attacks against finance, HR, procurement, and executive teams.

Synthetic voice scams and AI-assisted impersonation are also becoming more common in fraud investigations globally. Attackers are increasingly using cloned voices, manipulated audio, or AI-generated communication patterns to imitate executives, suppliers, or internal stakeholders during payment diversion attempts and urgent operational requests. Traditional “does this sound legitimate?” judgment calls are becoming less reliable as a standalone control.

The defensive response is not panic about AI itself — it is strengthening the operational controls that social engineering still has to pass through: phishing-resistant MFA, payment verification procedures, identity assurance, conditional access policies, security awareness training, and detection content aligned with modern social-engineering tradecraft. Organisations that treat AI-assisted attacks as an identity and process problem rather than purely a technology problem are adapting faster.

Key Takeaways

  • Ransomware affiliate tradecraft is more stable than ransomware brand names — focus detection on the techniques.
  • Business email compromise is still the most frequent loss event reported to SA insurers and SABRIC.
  • Mobile-money and banking fraud are uniquely African pressures, global threat reports underweight.
  • Identity-led intrusions are the dominant initial access pattern in current casework.
  • SaaS supply-chain compromise is now mainstream — monitor third-party posture continuously, not annually.
  • AI-assisted phishing, impersonation, and reconnaissance are increasing the quality and scale of social-engineering attacks — strengthening identity controls and verification processes is becoming critical.

How Cyber Resilience Can Help

Cyber Resilience helps organisations align detection content, threat hunting, and response planning to current adversary tradecraft through intelligence-informed MSS programmes.

Speak to our team to arrange a threat-intelligence and detection review discussion.

Seyton Hayes

Technical Director | Digital Forensics & Incident Response Specialist

Seyton Hayes is a cybersecurity specialist with more than 25 years of experience across enterprise security, incident response, digital forensics, and operational resilience.

Having previously led breach response and digital forensics capabilities within complex banking environments, Seyton specialises in helping organisations investigate incidents, strengthen security operations, and respond effectively to evolving cyber threats.Seyton’s technical leadership and practical experience in defending large-scale enterprise environments make him a trusted advisor to organisations seeking to strengthen operational resilience and respond effectively to evolving cyber threats.

Expertise

Incident Response • Digital Forensics • Threat Intelligence • Security Operations • Ethical Hacking

Frequently asked questions

What is the difference between threat intelligence and threat hunting?

Threat intelligence is the input — information about adversaries, techniques, infrastructure, and trends. Threat hunting is the operational activity — analysts actively searching environments for evidence of those threats, beyond what automated detection surfaces. Good intelligence without hunting becomes a newsletter; hunting without intelligence becomes noise.

Where do most South African organisations get their threat intelligence?

A mix: commercial feeds (Mandiant, CrowdStrike, Recorded Future, Anomali), free public sources (CISA advisories, ENISA, MITRE ATT&CK), sector ISACs where available, peer-network sharing through SABRIC for financial services, and vendor-specific feeds from EDR and email security providers. The mix matters less than whether the intelligence is fed into detection content and decisions.

How often should detection content be updated against new threats?

Continuously. Detection content is a living artefact, not a deliverable. Most managed services refresh detection rules weekly or monthly based on current threat intelligence, with significant emerging threats triggering out-of-cycle updates. Static detection content ages quickly.

Is threat intelligence worth the spend for mid-market organisations?

Yes, but rarely as a standalone subscription. Threat intelligence is most valuable when it is consumed by a detection function (in-house or managed) and translated into rules, hunts, and tabletop scenarios. For mid-market organisations, accessing it through a managed detection service is usually more practical than buying feeds directly.

Related Insights

Cyber resilience insights grounded in operational reality.

Practical guidance, operational perspectives, regulatory insights, and forensic-led thinking across cybersecurity, governance, resilience, and digital risk.

Need Clarity on your CURRENT RESILIENCE POSTURE?

Whether you need a focused assessment, operational support, governance maturity, or incident response guid-ance, we will help you understand your current position and build a practical path forward.