The Numbers Behind the Warning
INTERPOL's African Cyberthreat Assessment Report 2026, released August 3, 2026 and built from law-enforcement data submitted by 36 member countries, singles out South Africa as the continent's most attacked jurisdiction. The country accounted for 92% of Africa's detected ransomware incidents, 70% of business email compromise cases, and 213,523 DDoS attacks over the assessment period — including a single flood that peaked at 312 gigabits per second. Continent-wide, INTERPOL says artificial intelligence now drives 55% of reported cybercrime, and reported losses across Africa more than doubled, from $192 million in 2024 to $484 million in 2025.
South Africa's exposure is partly a function of success. It has the continent's most developed digital economy, the deepest data-centre and subsea-cable footprint, and the widest base of banks, insurers and cloud-dependent firms worth attacking — INTERPOL itself frames the region's "ultra-high connectivity" as the reason it draws threat actors "seeking maximum disruption." That's a comment on the country's digital maturity as much as its defenses. But a 92% ransomware share and a 70% BEC share are disproportionate even to that maturity, and the report is right to treat them as a warning rather than a footnote.
A Law With No Muscle Behind It
South Africa is not short on cybercrime statute. The Cybercrimes Act, 19 of 2020, gives police search-and-seizure powers over digital evidence, criminalises unlawful access and interception, and imposes a 72-hour breach-reporting duty on electronic communications providers. It traces back to a combined Cybercrimes and Cybersecurity Bill introduced to Parliament in 2017; the National Council of Provinces passed the cybercrimes half on 1 July 2020, and the President signed it into law on 26 May 2021. The "cybersecurity" half of that original bill — critical-infrastructure protection, a coordinating national body, mandatory incident-response structures — was stripped out during that process, and a standalone Cybersecurity Bill has circulated without reaching the statute book since.
The result is a country with real criminal offences on the books and comparatively little institutional infrastructure to enforce them. TechCentral reported this year that South Africa "does not have a dedicated cyber division" within the South African Police Service, only "fragmentation" — cybercrime investigation spread thinly across units without the specialised digital-forensics staffing the caseload requires. That is the gap the INTERPOL numbers land on: 213,523 DDoS attacks is not a caseload a handful of generalist investigators can triage, let alone the ransomware and BEC volume layered on top of it.
The Case for the Bill
There's a fair version of the argument for finally passing it. A statutory National Cybersecurity Centre would give SAPS, sector regulators and critical-infrastructure operators — banks, ports, the power utility, aviation control — a single coordinating point instead of today's patchwork, and mandatory sector CSIRTs would formalise incident response for the operators most likely to be hit next. INTERPOL's report notes ransomware actors have already shifted from opportunistic extortion toward infrastructure disruption, pointing to an attack on the South African Weather Service that degraded data feeds used for aviation and maritime routing. Proponents aren't wrong that five years of voluntary coordination hasn't closed the gap INTERPOL just measured.
Where Proportionality Should Bite
But the draft Cybersecurity Bill, as described by legal commentary tracking it, goes further than coordination. It would create a National Cybersecurity Champion role in the Deputy President's office and, more consequentially, layer in data-sovereignty and localisation requirements obliging data generated in South Africa to be processed under domestic rules "regardless of where it is processed." That provision does nothing to catch a ransomware operator abroad or train a forensic investigator at home — it raises compliance costs for the cloud and AI infrastructure providers South Africa is trying to attract, at the exact moment INTERPOL's own report says AI-enabled attacks are the variable reshaping the threat. A localisation mandate taxes the digital economy INTERPOL says is already the continent's most-targeted; it doesn't shrink the attack surface, it shrinks the pool of providers willing to build here.
The narrower, evidence-backed reforms — statutory incident-response coordination, sector CSIRTs, and above all funded SAPS digital-forensics capacity — track directly to the gap the report documents. Parliament should move those pieces and treat data-localisation provisions as a separate question requiring its own economic-impact review, not a rider on a bill justified by a ransomware crisis it won't actually touch.