Skip to content

africa occidentale

West Africa is fertile ground for cybercriminals. Le Monde Report

The increasing digitalization of West Africa is exposing its IT infrastructures to a growing number of cyberattacks, exacerbated by a shortage of qualified experts, limited resources, and still underdeveloped regulations regarding cybersecurity.

In this part of the continent, cybersecurity is not progressing at the same pace as the Internet. As a result, West Africa’s digital infrastructures remain vulnerable, mainly due to the lack of qualified experts, writes Le Monde.

THE CYBERATTACK ON AIR CÔTE D’IVOIRE

The attack that hit Air Côte d’Ivoire on February 8 did not come from above, but from its IT system. The company was the victim of ransomware that led to the exfiltration and encryption of 208 gigabytes of sensitive data. Faced with its refusal to pay, the hackers made the data public on February 23.

This is a well-known “double extortion” type attack: hackers steal data before encrypting it with ransomware software, then demand a ransom payment in exchange for not disclosing and decrypting it.

This cyberattack is the second most serious ever recorded in Côte d’Ivoire, after the 2023 attack targeting the police forces and affecting nearly 40,000 officers. This time, the consequences could go beyond Ivorian borders, as the company serves West and Central Africa, with connections to South Africa, Morocco, and more recently, France.

CLAIMED BY THE INC RANSOM GROUP

The attack was claimed by the Inc Ransom group, active for two years and reportedly causing about 680 victims worldwide. On February 19, it listed the company on its dark web site that catalogs its targets. The information was shared on X by cybersecurity expert Clément Domingo, known as “SaxX.” Among the compromised data are financial and human resources information, contracts, and passengers’ personal data, dating back at least to 2012.

A SERIES OF CYBERATTACKS IN WEST AFRICA

This episode is just the latest in a long series of similar cyberattacks in West Africa. In early February, Senegal was hit by an attack on the Directorate of File Automation, the national agency responsible for identity cards, passports, and biometric data, which caused the temporary suspension of national identity card production. In October 2025, the Senegalese General Directorate of Taxes and Domains suffered a similar attack, with the exfiltration of about one terabyte of data.

GHANA, NIGERIA, GUINEA, AND MALI UNDER DDOS ATTACKS IN 2024

In 2024, Ghana, Nigeria, Guinea, and Mali were among the countries most affected by denial of service (DDoS) attacks, a type of attack that overloads servers making them unavailable. In the same year, Côte d’Ivoire recorded over 27 million intrusion attempts detected by its monitoring systems, of which 37% targeted industrial infrastructures and nearly 10,000 targeted the financial sector, according to Kaspersky Security Network.

“Cybercrime is a growing concern in West Africa due to increased use of technologies and the spread of the Internet in the region,” emphasizes a report from Cornell University published on January 7, 2024. In recent years, the region has indeed experienced a strong digital acceleration, with the connected population rising from 62% in 2020 to 74% in 2023.

POORLY CLASSIFIED CYBERATTACKS

But cybersecurity is not advancing at the same pace. West Africa’s digital infrastructures remain vulnerable, particularly due to insufficient resources and a shortage of qualified experts.

“Africa has become the playground of cybercriminals,” summarizes SaxX. Unlike the European Union, which has a structured regulatory framework with the General Data Protection Regulation and the NIS 2 Directive (Network and Information Security), one relating to personal data and the other to information systems, many African countries lag behind in legislation and IT governance.

THE MALABO CONVENTION RATIFIED BY ONLY 20 STATES

Adopted in June 2014, the Malabo Convention aimed to harmonize continental standards on cybersecurity and data protection. However, only about twenty African states have ratified it, and few have fully operational national agencies. Côte d’Ivoire established ANSSI in 2024, but its resources remain limited.

Moreover, cyberattacks remain largely underestimated. In the absence of systematic disclosure mechanisms, their scope is often minimized.

COMPANIES PREFER TO GIVE IN TO RANSOMS

For fear of damaging their reputation, some companies prefer to quietly pay ransoms rather than make intrusions public. Other cases are revealed only thanks to leaks or claims by criminal groups. In April 2023, when a massive cyberattack carried out by the Russian hackers BlackCat paralyzed the African Union’s IT system, the institution tried to cover up the incident.

Some countries are exceptions, however. Benin, in particular, has undertaken a structured effort in recent years on cybersecurity, developing specialized institutions, participating in international competitions to identify talents, and increasing involvement in specialized forums. A model that other states in the region, such as Senegal or Côte d’Ivoire, still struggle to match.

 

(Excerpt from the foreign press review curated by eprcomunicazione)

Back To Top