South African companies that are hacked pay an average of R5.01 million in ransom
The median South African ransom payment in 2026 was R5.01 million, while the average demand was R7 million.
This marks a decrease of 28% and 57% from 2025, respectively.
However, the average cost of recovering from a ransomware attack in South Africa was R17.73 million, excluding ransom payments.
These statistics were revealed in cybersecurity firm Sophos’ 2026 report, titled ‘The State of Ransomware in South Africa’.
This report compiles findings from an independent, vendor-agnostic survey of 135 South African organisations that were hit by ransomware over the past year.
Now in its seventh year, Sophos’ report found that 63% of attacks in 2026 resulted in data being encrypted.
This puts South Africa above the global average of 56%, and marks an increase from the 60% reported by local respondents in 2025.
At a media event in Johannesburg in September, Sophos’ SADC regional head, Pieter Nel, explained that ransomware attacks have emerged as a potent threat to South African companies.
“Once attackers are able to encrypt data, the organisation faces the immediate challenge of restoring systems, maintaining operations and managing the financial and human impact of the incident,” Nel said.
He explained that it is no longer a matter of “if” a firm will get attacked, but rather when.
Nel identified the root cause of firms falling victim to ransomware attacks as inefficient cybersecurity, which affected 47% of survey respondents.
This is the highest of any country surveyed in Sophos’ global ransomware report, which included 2,158 participants across 17 countries.
Nel said the prominence of ransomware attacks is causing anxiety for many firms at the C-suite level, with this threat having become a $1 million problem in South Africa.
This is because, excluding any ransom payments, the average recovery cost for South African organisations after their ransomware attack was $1.08 million (R17.73 million).
This includes the costs of downtime, people time, device cost, network cost, and lost opportunity.
Positively, Sophos found that the median South African ransom payment was R5.01 million, a 28% drop from R6.98 million in the 2025 report.
Sophos also reported that South African organisations now typically pay 71% of the median ransom demand, the lowest of any country surveyed, compared to 64% in 2025.
In addition, 40% of South African firms recovered from a ransomware attack within a week, also the lowest of any country surveyed and a notable drop from 47% in the 2025 report.

‘This is not hacking as you know it’
At the same media event, Sophos solutions engineer Lukas Pelser explained that the way hackers attempt to gain access to a company’s data has changed.
In many cases, attempts have become simpler, with hackers looking for the easiest way in.
He described one case where a firm’s employee logged a support case with the internal IT department.
Once the ticket was logged, bad actors reached out to the employee posing as an IT representative of the firm.
The employee then allowed them to install technology control points on their work computer, which the bad actors used to install malware.
“This is not hacking as you know it – it’s simple stuff,” Pelser said, adding that many people are still under the impression that hacking involves one person spending hours to break past firewalls.
Concerningly, he said there has been a rise in phishing attacks, particularly via email, that are more personalised.
This is partly because phishing simulation tools are becoming increasingly effective, allowing bad actors to more accurately pose as someone within the firm they are targeting.
One of Sophos’ recommendations to South African firms to protect against attacks was to prioritise email security.
It explained that phishing and malicious email account for over one-third of ransomware root causes in South Africa.
Therefore, organisations should deploy advanced email filtering, implement DMARC/DKIM/SPF protocols, and invest in regular phishing awareness training.
For attacks that did not originate through email or phishing, user devices were the most common entry point, accounting for 43% of incidents.
Comments