Phishing and social engineering are the most significant risks

February 2026 News & Events, Information Security

ESET Research has released its latest threat report summarising the threat landscape trends observed in ESET telemetry and analysed by ESET threat detection and research experts in the second half of 2025. According to the data, in South Africa, phishing remains the highest-risk category, accounting for 45,7% of detected threats, compared with 32,5% across Africa.


Tony Anscombe.

“Phishing remains the leading initial access vector affecting South African companies,” says Tony Anscombe, chief security evangelist at ESET. “The higher proportion of phishing detections reflects both attacker focus and the continued effectiveness of social engineering. Attackers are prioritising threats that allow them a greater opportunity for monetisation.”

While phishing dominates the South African market, scam activity has accelerated globally. According to the report, detections of HTML-based scam campaigns, such as the Nomani investment scam, have grown by 62% over the past year. In ESET telemetry, detections of Nomani scams grew 62% year-over-year, with the trend slowing slightly in H2 2025. Nomani scams have recently expanded beyond Meta to other platforms, including YouTube. These threats have come with improved techniques, including higher-resolution deepfake videos, AI-generated phishing websites, and short-lived advertising campaigns, which are increasingly difficult to detect.

AI remains a pervasive threat, both locally and abroad. In the second half of 2025, ESET discovered PromptLock, the first known AI-driven ransomware capable of generating malicious scripts on demand at high speed. While AI is primarily used to craft convincing phishing and scam content, PromptLock is an example of a growing body of AI-driven, intelligent threats that signal a new era in cybercrime.

NFC threats are also gaining momentum, growing in both scale and sophistication, with an 87% increase in ESET telemetry and with notable upgrades and campaigns observed in the second half of 2025. Anscombe notes that South Africa’s widespread reliance on card-based payment systems makes this class of attack more relevant than in regions where mobile money platforms dominate. These attacks rely on social engineering to persuade victims to install malicious Android applications that relay card data and PINs in real time.

Ransomware continues to gain global momentum, with ESET Research projecting a 40% year-on-year increase in publicly reported ransomware victims compared with 2024. While South Africa is not one of the most affected countries globally – the largest number of analysed ransomware attacks were aimed at companies in the United States, followed by Spain, France, Italy and Canada – Anscombe points out that South African organisations have experienced a number of ransomware incidents during the reporting period.

Two of the ransomware-as-a-service solutions dominating the market at present are Akira and Qilin, with a newcomer, Warlock, introducing innovative evasion techniques. EDR killers are proliferating as well, underscoring the relevance of endpoint detection and response tools in mitigating the threat.

South Africa is also actively participating in efforts to counter cybercrime. The country participated in Operation Sentinel, a joint law enforcement initiative coordinated by INTERPOL and AFRIPOL, resulting in 574 arrests and the recovery of approximately $3 million linked to cyber-enabled crimes. 

For more information, check out the ESET Threat Report H2 2025 on WeLiveSecurity.com.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
Duxbury SA Milesight distributor
Duxbury Networking News & Events Surveillance
Duxbury Networking has been appointed the exclusive distributor of Milesight surveillance solutions in South Africa, expanding its surveillance portfolio with a platform designed to deliver AI-driven analytics, rapid deployment, and open integration for modern security environments.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
SMARTpod talks about HomeSec Expo 2026
SMART Security Solutions Technews Publishing News & Events Residential Estate (Industry) Videos
SMARTpod, the podcast from SMART Security Solutions, finds out more about the upcoming HomeSec Expo happening at Gallagher Estate on 4 & 5 March 2026.

Read more...
“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Coordinated efforts lead to successful crime response
News & Events Surveillance Integrated Solutions
A synchronised operation involving Vumacam’s control room operators, the Johannesburg Metropolitan Police Department (JMPD), and 24/7 Drone Force, resulted in the successful identification and apprehension of a suspect linked to a reported theft case.

Read more...
2025 Global OSPAs winners
News & Events
Bringing together the very best of the global security industry, the second Global Outstanding Security Performance Awards (OSPAs) was streamed live to a worldwide audience on 05 February 2026.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
Exhibitions across the security spectrum
News & Events Perimeter Security, Alarms & Intruder Detection Smart Home Automation
HomeSec Expo has become the security industry’s premier trade event. Visitors will experience a live showcase of how different aspects of the security spectrum come together under one roof.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.