Group Purchasing
Group Purchasing

Africa's Ransomware Landscape in 2026: Who's Attacking, How They Get In, and How to Defend

  • Thu, Dec 3, 2026
  • 2:00PM - 3:00PM SAST
  • English
  • Ismael Valenzuela
  • Technical Presentation
Login to register
Webcast Hero

Ransomware across Africa is growing and becoming more professionalised. Global Ransomware-as-a-Service groups are reaching deeper into the continent, and several are hitting African organisations at a rate well above their global footprint. Law enforcement action against major operators like LockBit and ALPHV hasn't reduced the threat—it has scattered it across a wider, harder-to-track set of actors.

In this session, Ismael Valenzuela, SANS Author and Senior Instructor, breaks down the ransomware and extortion landscape facing African organisations: which groups are most active, how they get in, and which sectors and countries are most exposed. He then turns that intelligence into a prioritised set of defensive actions African security teams can implement now—grounded in local realities, from regional data protection law to resource constraints.

What the Session Covers

  • How the African ransomware ecosystem has shifted from a few dominant groups to a fragmented, multi-group landscape—and what that means for defenders
  • Profiles of the most active groups targeting Africa in 2026, including those with an outsized regional focus
  • Why edge devices and external remote access (VPNs, firewalls, RDP) dominate initial access, and which vulnerabilities matter most
  • Emerging threats: data-theft-only extortion, RaaS cartelisation, AI-augmented attacks, and the regulatory exposure created by POPIA, Kenya's Data Protection Act, Nigeria's NDPA and similar laws
  • A prioritised defensive playbook: edge device hardening, phishing-resistant MFA, exfiltration detection, and incident response readiness

Who Should Attend

  • CISOs, security managers and IT leaders
  • SOC analysts, threat intelligence and incident response teams
  • Security architects and engineers responsible for remote access and edge infrastructure
  • Risk, compliance and data protection officers

Meet Your Speaker

Ismael Valenzuela
Ismael Valenzuela

Ismael Valenzuela

Vice President Threat Research & Intelligence at Arctic Wolf

Ismael is a Senior SANS Instructor and Arctic Wolf VP. Author of SEC530 and a prestigious GSE-certified expert, he blends decades of SOC, threat research, and community contributions to equip defenders with resilient, adversary-aware strategies.

Read more about Ismael Valenzuela