Threat intelligence only earns its name when it changes decisions. The patterns below are the ones our managed detection and response team is seeing most often across South African client environments — and they are the ones most worth feeding into detection content, tabletop scenarios, and board reporting this quarter.
The short answer
Five threat patterns are dominant in South African environments this year: ransomware affiliate operations targeting mid-market and enterprise, business email compromise tied to executive impersonation, mobile money and banking fraud, identity-led intrusions via stolen credentials, and supply chain compromise through third-party SaaS. Each maps to specific MITRE ATT&CK techniques.
Ransomware affiliates — operators below the headlines
Ransomware-as-a-service has decoupled the operators that develop the encryptor from the affiliates that gain initial access and execute. The implication for defenders: the named brand groups are interchangeable; the affiliate tradecraft is more stable. Detection focuses on the consistent affiliate techniques — credential abuse, BloodHound and ADRecon reconnaissance, RDP and VPN abuse, and double-extortion data staging.
Business email compromise — still the highest-frequency loss event
BEC remains the most frequently reported loss event by South African organisations to insurers and SABRIC. Executive impersonation, supplier invoice redirection, and payroll diversion are the recurring scenarios. The control set is well understood — DMARC enforcement, mailbox rule monitoring, out-of-band payment verification, callback procedures on changes — but adoption is uneven. AI-generated content has raised the quality of social engineering lures.
Mobile-money and banking fraud — uniquely African pressure
The continent’s mobile-money penetration and the maturity of South African banking digital channels produce a fraud landscape that does not map neatly to global threat reports. SIM swap, vishing, and in-application abuse persist alongside SS7 attacks against MFA via SMS. The defensive answer is identity hardening on the customer side and transaction monitoring on the institution side.
Identity-led intrusion — the credential is still the front door
Most intrusions in our caseload begin with a credential: stolen, credential-stuffed, password-sprayed, or phished. Once inside, attackers move laterally through identity infrastructure — Kerberoasting, AS-REP roasting, golden ticket creation, abuse of conditional-access misconfigurations. Detection coverage against ATT&CK Discovery and Lateral Movement techniques produces the biggest improvement in mean time to detect.
Supply-chain compromise via SaaS — the new flank
As organisations push more workloads to SaaS, third-party identity providers, ticketing systems, code repositories, and finance platforms become attractive intermediate targets. Compromising a SaaS vendor’s OAuth tokens or API keys across many customer tenants is now a documented pattern. Third-party risk management programmes that monitor SaaS posture continuously close this gap; questionnaire-based reviews do not.
These threat patterns increasingly affect operational continuity, fraud exposure, cyber insurance reviews, and executive reporting — not just security tooling decisions.
AI-assisted social engineering and reconnaissance
Generative AI has lowered the effort required to run convincing social-engineering campaigns at scale. Phishing emails are now better written, more context-aware, and increasingly personalised using publicly available organisational and executive information gathered during reconnaissance. Multilingual lures that previously exposed attackers’ mistakes are becoming harder for employees to identify, particularly in environments that operate across English and multiple regional languages.
AI-assisted reconnaissance is also accelerating how attackers profile organisations before targeting them. Public LinkedIn activity, supplier relationships, executive structures, procurement notices, breached credential databases, and exposed cloud services can now be aggregated and analysed far faster than traditional manual profiling allowed. The result is more convincing impersonation attempts and better-targeted attacks against finance, HR, procurement, and executive teams.
Synthetic voice scams and AI-assisted impersonation are also becoming more common in fraud investigations globally. Attackers are increasingly using cloned voices, manipulated audio, or AI-generated communication patterns to imitate executives, suppliers, or internal stakeholders during payment diversion attempts and urgent operational requests. Traditional “does this sound legitimate?” judgment calls are becoming less reliable as a standalone control.
The defensive response is not panic about AI itself — it is strengthening the operational controls that social engineering still has to pass through: phishing-resistant MFA, payment verification procedures, identity assurance, conditional access policies, security awareness training, and detection content aligned with modern social-engineering tradecraft. Organisations that treat AI-assisted attacks as an identity and process problem rather than purely a technology problem are adapting faster.
Key Takeaways
- Ransomware affiliate tradecraft is more stable than ransomware brand names — focus detection on the techniques.
- Business email compromise is still the most frequent loss event reported to SA insurers and SABRIC.
- Mobile-money and banking fraud are uniquely African pressures, global threat reports underweight.
- Identity-led intrusions are the dominant initial access pattern in current casework.
- SaaS supply-chain compromise is now mainstream — monitor third-party posture continuously, not annually.
- AI-assisted phishing, impersonation, and reconnaissance are increasing the quality and scale of social-engineering attacks — strengthening identity controls and verification processes is becoming critical.
How Cyber Resilience Can Help
Cyber Resilience helps organisations align detection content, threat hunting, and response planning to current adversary tradecraft through intelligence-informed MSS programmes.
Speak to our team to arrange a threat-intelligence and detection review discussion.
