Africa
Primarily a target
—
188 received·
6 initiated·
30 responses
·54 countries
Across the full record, 189 cyber operations involving Africa were added to the database. The all-time mean Intensity of cyber operations involving Africa is 2.6.
Maintained by EuRepoC research analysts · updated 05 Oct 2026
For all time, this region appears chiefly as a target — 188 incidents directed at it, 6 it is linked to initiating.
Source: EuRepoC Global Database as of 05 Oct 2026.
01 / 02
188 incidents · as targetCyber activity
Incidents directed at targets in Africa, and the responses they drew.
Cyber incident intensity
Mean2.6/15Moderate
Range 1.0–8.0
Drag the ends of the observed range to narrow intensities.
185 coded incidents · All time
Database additions by yearincidents against Africa
Bar height shows incidents added during all time; select a bar to filter this interval; hover for average intensity.
Most-targeted sectorswhat gets hit
SectorIncidentsIntensityResponded
Government / ministries
2.4Moderate
11/72
Corporate Targets
2.8Moderate
4/46
Finance
3.0Moderate
5/31
Telecommunications
3.3Moderate
5/31
Civil service / administration
3.4Moderate
8/24
Transportation
3.1Moderate
3/20
Unknown
3.6Moderate
4/17
Energy
3.9Moderate
5/15
Government / ministries is the most-targeted sector — 72 of 188 incidents, 11 answered.
By originwho is behind activity against it
China
33incidents
avg 3.1 · Moderate
Russia
12incidents
avg 3.3 · Moderate
Iran, Islamic Republic of
11incidents
avg 3.3 · Moderate
Morocco
7incidents
avg 1.6 · Moderate
United States
5incidents
avg 2.4 · Moderate
Korea, Democratic People's Republic of
4incidents
avg 2.8 · Moderate
Togo
2incidents
avg 3.5 · Moderate
Bangladesh
2incidents
avg 1.0 · Moderate
Nigeria
2incidents
avg 2.5 · Moderate
United Kingdom
2incidents
avg 1.5 · Moderate
Kenya
1incident
avg 2.0 · Moderate
Australia
1incident
avg 0.0 · Moderate
Kazakhstan
1incident
avg 3.0 · Moderate
Vietnam
1incident
avg 3.0 · Moderate
United Arab Emirates
1incident
avg 1.0 · Moderate
Portugal
1incident
avg 1.0 · Moderate
India
1incident
avg 1.0 · Moderate
Turkey
1incident
avg 1.0 · Moderate
Germany
1incident
avg 3.0 · Moderate
Showing 8 of 19
02 / 02
Incidents received & responses
Unknown
South Africa
·Water
Unknown Threat Actors Disrupted Payment Software And Geographic Information System Of Rand Water In South Africa On 2 September 2026
2 Sep 2026
Incident · Unattributed
2 Sep 2026
Unknown
South Africa
·Water
Unknown Threat Actors Disrupted Payment Software And Geographic Information System Of Rand Water In South Africa On 2 September 2026
RansomHouse
Namibia
·Government / ministries +1
RansomHouse Ransomware Group Breached Ministry of Defence and Veterans Affairs in Namibia in September 2026
1 Sep 2026
Incident · Low severity
1 Sep 2026
RansomHouse
Namibia
·Government / ministries +1
RansomHouse Ransomware Group Breached Ministry of Defence and Veterans Affairs in Namibia in September 2026
Unknown
Angola
·Telecommunications
Unknown Threat Actor Disrupted Mobile Voice, Data and Internet Services of Telecommunications Company Unitel in Angola on 28 July 2026
28 Jul 2026
Incident · Unattributed
28 Jul 2026
Unknown
Angola
·Telecommunications
Unknown Threat Actor Disrupted Mobile Voice, Data and Internet Services of Telecommunications Company Unitel in Angola on 28 July 2026
Unknown
Kenya
·Government / ministries
Unattributed Hacker Defaced Kenyan President's Website On 18 July 2026
18 Jul 2026
Incident · Unattributed
18 Jul 2026
Unknown
Kenya
·Government / ministries
Unattributed Hacker Defaced Kenyan President's Website On 18 July 2026
INC Ransom
USCOCHAE+185189 countries
·Unknown +2
INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026
22 Jun 2026
Incident · Low severity
22 Jun 2026
INC Ransom
USCOCHAE+185189 countries
·Unknown +2
INC Ransomware Group Exploited Zero-Day Vulnerability in Remote Access Gateway SonicWall SMA1000 Affecting Private and Governmental Organizations in Multiple Countries since 22 June 2026
USCybersecurity and Infrastructure Security Agency
Andorra
US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026
Technical disclosure
22 Jun 2026
Technical disclosure
22 Jun 2026
USCybersecurity and Infrastructure Security Agency
Andorra
US CISA Issued an Alert on Hardening Compromised Fortinet Devices after Reports of Credential Exposures, 22 June 2026
GBUnited Kingdom’s National Cyber Security Centre
Andorra
UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026
Technical disclosure
19 Jun 2026
Technical disclosure
19 Jun 2026
GBUnited Kingdom’s National Cyber Security Centre
Andorra
UK National Cyber Security Centre Issued Guidance on Fortinet Firewalls and VPN Gateways Targeting on 19 June 2026
ITNational Cybersecurity Agency
Andorra
Italian Cyber Security Agency (ACN) Published Bulletin on Threat Actor Leaks FortiGate SSL-VPN Dataset ('FortiBleed'), 18 June 2026
Technical disclosure
18 Jun 2026
Technical disclosure
18 Jun 2026
ITNational Cybersecurity Agency
Andorra
Italian Cyber Security Agency (ACN) Published Bulletin on Threat Actor Leaks FortiGate SSL-VPN Dataset ('FortiBleed'), 18 June 2026
Showing the 8 most recent of 218
Open all in advanced search