Ransomware is now a documented risk for African banks. INTERPOL's Africa Cyberthreat Assessment Report 2026 finds South Africa accounted for 92% of the ransomware detections its data partner recorded across Africa, and describes East Africa as a hub of mobile money fraud and infrastructure-targeted ransomware. The combination of growing digital infrastructure, increasing connectivity, and security programmes that have not yet caught up with the threat makes banks across the continent, East African institutions included, attractive targets for ransomware operators.
This guide covers the threat, the controls that prevent attacks, detection before encryption begins, recovery when prevention fails, and what the National Bank of Rwanda (BNR) expects in reporting and preparedness.
The ransomware threat landscape in Africa
Ransomware groups operate as businesses. They target organisations that have valuable data, high pressure to restore services quickly, and the financial capacity to pay. African banks tick all three boxes.
The pattern across the continent:
- Ransomware-as-a-Service (RaaS) groups such as LockBit, BlackCat (ALPHV), and their successors have expanded their targeting to include African financial institutions
- Double extortion is standard: attackers encrypt systems and exfiltrate data, threatening to publish sensitive customer information if the ransom is not paid
- The pre-encryption window is short: Mandiant's M-Trends 2026 report puts the global median dwell time at 14 days, and in 44% of ransomware cases the first notice the victim received came from the attacker; attackers use that window to map the environment, disable backups, and maximise impact
- Third-party vectors: attackers compromise a technology vendor or managed service provider to gain access to multiple banking clients simultaneously
- Ransom demands are calibrated: operators research the institution's revenue and insurance position and set the demand at what they believe it can pay
The ransom is the smaller cost. Even if you never pay, a ransomware attack on a bank means days to weeks of disrupted services, regulatory scrutiny, incident response costs, breach notification obligations, and the cost of rebuilding compromised systems. For African banks, where digital trust is still being established, the reputational damage can be particularly severe.
How ransomware gets into banks
Ransomware attacks against financial institutions typically follow a predictable pattern, and each stage is a chance to stop them.
Initial access
Sophos's State of Ransomware 2026 survey found malicious email (26%) and phishing (24%) the most commonly identified root causes of an attack, followed by compromised credentials (23%) and exploited vulnerabilities (18%). Across all breaches, ransomware or otherwise, Verizon's 2026 Data Breach Investigations Report (DBIR) found vulnerability exploitation the most common initial access vector (31%). The entry points that matter in banking environments:
- Exploited internet-facing systems: unpatched VPN appliances, web application vulnerabilities, exposed Remote Desktop Protocol (RDP) services, and vulnerable mail servers. These are exactly the kinds of vulnerabilities a penetration test is designed to find, and that external attack-surface monitoring catches when they appear between tests
- Compromised credentials: stolen or weak passwords used for remote access, VPN, email, or admin interfaces. Credential stuffing from breached databases is increasingly common
- Phishing emails: a staff member clicks a malicious link or opens a weaponised attachment. Sustained, measured phishing simulation and awareness training is the most reliable control here; see IMIZI Aware
- Third-party compromise: attackers gain access through a vendor's VPN connection, remote support tool, or shared infrastructure. The March 2026 bank fraud in Rwanda demonstrated how vendor access can become an attack vector
- Supply chain attacks: compromised software updates or tools from technology providers
Post-exploitation and lateral movement
After gaining initial access, ransomware operators hold off on encryption and spend the dwell window, often days to a couple of weeks, on:
- Escalating privileges to domain administrator
- Mapping the Active Directory environment
- Identifying backup systems and their locations
- Moving laterally to reach critical servers (core banking, databases, file servers)
- Exfiltrating sensitive data to use as a double-extortion threat
- Disabling or deleting backups to ensure the victim cannot recover without paying
- Deploying persistence mechanisms to maintain access even if some footholds are discovered
Deployment
Once positioned, the attackers deploy ransomware across the environment simultaneously, often out of hours (Friday evening or holiday weekends) to maximise the window before detection and response.
Prevention controls
These controls directly reduce the probability of a successful ransomware attack.
Patch management
Keep all systems current, especially internet-facing infrastructure. VPN appliances, firewalls, email servers, and web applications must be patched promptly when security updates are released. Verizon's 2026 DBIR ranks vulnerability exploitation as the most common initial access vector for breaches, and Mandiant's M-Trends 2026 puts exploits at the top of its initial infection vectors (32%); prompt patching of internet-facing systems closes that route.
Priority targets: VPN concentrators (Fortinet, Ivanti Connect Secure (formerly Pulse Secure), Citrix), Microsoft Exchange, web application frameworks, and any internet-facing management interface.
Email security
Deploy multi-layered email defences:
- Email gateway filtering with attachment sandboxing
- DMARC, DKIM, and SPF to prevent email spoofing
- Link rewriting and URL scanning
- Blocking macro-enabled Office documents from external senders
- A user reporting mechanism for suspicious emails
Network segmentation
Segment your network so that a compromise in one area cannot spread to the entire environment:
- Separate core banking systems from the corporate network
- Isolate backup infrastructure on a dedicated network segment
- Segment internet-facing systems (DMZ) from internal systems
- Implement micro-segmentation for critical workloads
- Control east-west traffic as well as north-south
Network segmentation is the single most effective architectural control against ransomware. If your network is flat, a single compromised workstation gives the attacker access to everything.
Privileged access management
- Implement multi-factor authentication for all administrative access
- Use privileged access management (PAM) tooling for domain admin and service accounts
- Remove standing admin privileges from user workstations (no local admin rights for daily use)
- Implement just-in-time (JIT) access for privileged operations
- Monitor and alert on all privileged authentication events
Backup architecture
Your backup infrastructure is a primary target for ransomware operators. Protect it accordingly:
- Air-gapped or immutable backups: at least one backup copy must be offline or immutable (cannot be modified or deleted even by an administrator)
- 3-2-1 rule: three copies of data, on two different media types, with one off-site
- Backup integrity testing: regularly restore from backups to verify they work; an untested backup cannot be relied on in an incident
- Separate credentials: backup systems should use different credentials from the production Active Directory
- Encrypted backups: protect backup data against exfiltration
Test your backups. Institutions often run backup systems for years without ever testing a full restoration. The worst time to discover that your backups are corrupted, incomplete, or too slow to restore is during a ransomware incident. Schedule quarterly backup restoration tests for critical systems.
Application security
Reduce the web application attack surface through regular penetration testing and secure development practices. Web applications and APIs are common initial access vectors, especially in banking environments with customer-facing portals and mobile banking backends. See our API security guide for banking-specific considerations.
Detection capabilities
Prevention will not stop everything. Detection capabilities determine whether a ransomware attack is caught in the early stages (when damage can be limited) or after encryption has begun (when options are severely limited).
What to monitor
- Endpoint detection and response (EDR): deploy EDR on all endpoints and servers. EDR tools detect the behavioural patterns of ransomware (rapid file encryption, process injection, privilege escalation) even when the specific malware variant is unknown
- Security information and event management (SIEM) with relevant detection rules: collect logs from Active Directory, endpoint protection, network devices, email gateway, and VPN. Alert on mass file rename events, unusual service account activity, new administrative account creation, large data transfers to external destinations, and lateral movement patterns
- Network detection: monitor for unusual Server Message Block (SMB) traffic patterns, Cobalt Strike or other command-and-control (C2) framework beacons, DNS tunnelling, and connections to known malicious infrastructure
- Active Directory monitoring: alert on changes to domain admin groups, Group Policy modifications, new service accounts, and DCSync or DCShadow activity
Detection timeline
The window between initial access and ransomware deployment is your opportunity, and it is usually measured in days. Mandiant's M-Trends 2026 report puts the global median dwell time at 14 days across all intrusions, and in 44% of ransomware cases the victim learned of the intrusion from the attacker. If you detect the intrusion during this window, you can contain the incident before encryption occurs.
Key metrics:
- Mean time to detect (MTTD): how quickly you identify that something is wrong
- Mean time to respond (MTTR): how quickly you can contain the threat after detection
For banks without a dedicated security operations centre (SOC), managed detection and response (MDR) services can provide 24/7 monitoring and alerting at a fraction of the cost of building one in-house.
Recovery planning
When ransomware successfully encrypts systems, your recovery capability determines the outcome.
Immediate actions (first hour)
- Isolate: disconnect affected systems from the network immediately. Physically unplug network cables if necessary; disabling Wi-Fi alone is not enough
- Contain: identify the scope of encryption and isolate unaffected systems before the ransomware spreads further
- Preserve evidence: capture memory images and disk images of affected systems before any remediation. You will need these for investigation and potentially for law enforcement
- Activate the incident response plan: invoke your incident response team and plan
- Assess backup status: determine whether backups are intact, accessible, and not encrypted
Recovery process
- Identify the ransomware variant: this determines whether free decryptors are available (some older variants have been cracked by security researchers)
- Assess the damage: which systems are encrypted, which are clean, what data was exfiltrated
- Rebuild from clean images: do not attempt to "clean" encrypted systems. Rebuild from known-good images or install fresh
- Restore data from backups: restore from the most recent clean backup, verifying integrity at each step
- Validate before reconnecting: ensure restored systems are clean before reconnecting them to the network
- Implement enhanced monitoring: increase monitoring intensity during the recovery period. Attackers sometimes maintain secondary access and return
The ransom question
We advise against paying ransoms. The reasons:
- Payment funds criminal operations and incentivises further attacks
- Payment does not guarantee decryption, and some groups provide decryptors that only partially work
- Payment marks your institution as willing to pay, increasing the likelihood of repeat targeting
- Even with decryption, you cannot trust that exfiltrated data will be deleted
- Paying criminal organisations can create regulatory and legal complications
Investing in prevention, detection, and backups, so that payment never needs to be considered, costs less than a ransom and its fallout.
BNR reporting requirements
A ransomware attack on a BNR-supervised institution is a reportable cyber incident. BNR expects the following (see our guide to BNR cybersecurity requirements):
- Prompt notification to BNR upon discovery of the attack
- Initial report covering the nature of the attack, systems affected, customer data at risk, containment actions taken, and business continuity status
- Progress updates as the situation evolves
- Final incident report with root cause analysis, full impact assessment, remediation actions taken, and measures to prevent recurrence
Failure to report, or delayed reporting, can result in regulatory action on top of the operational damage from the attack itself.
Building ransomware resilience
A ransomware-resilient bank combines:
- Regular penetration testing to find and fix the vulnerabilities that enable initial access
- Network segmentation to limit the blast radius of any compromise
- EDR and monitoring to detect attackers during the pre-encryption dwell time
- Immutable backups to ensure recovery without ransom payment
- Tested incident response plans so the team knows what to do when the alert fires
- Security awareness training to cut the phishing and credential-theft routes into the bank (see our security awareness training service)
No single control is sufficient; together they make ransomware harder to execute and easier to recover from.
How we can help
IMIZI Cyber is a Kigali-based firm providing manual penetration testing for banks, fintechs, telecoms, government, and healthcare institutions across Africa. For ransomware resilience, that means penetration testing that finds the vulnerabilities ransomware operators exploit for initial access, security architecture review that evaluates segmentation and backup resilience, and incident response readiness assessments. Our team tests the environment and writes the report; the findings map directly to the prevention, detection, and recovery controls above, with evidence a board and a BNR examiner can both act on.
For full details on our methodology, see our penetration testing service page. For broader security programme assessments, see our security assessments service page. Book a Free Call to assess your institution's ransomware resilience.