WWISE and Information Regulator: Rise in data breaches puts influencers and everyday users at risk

WWISE and Information Regulator: Rise in data breaches puts influencers and everyday users at risk

South Africa Faces Surge in Cyberattacks as Data Breaches Rise 40%

South Africa is experiencing a sharp increase in cyber threats, with data breaches rising by 40% in recent months. The Information Regulator reported 2,374 security compromise notifications in the 2024/25 financial year nearly 200 incidents monthly while an additional 1,947 breaches were recorded between April and November 2025.

Cybercriminals are increasingly targeting individuals with strong online presences, particularly social media influencers, whose personal data may already be circulating on the dark web. Muhammad Ali, managing director of WWISE, warns that many South Africans underestimate their vulnerability, assuming hacking "won’t happen to me" until it does.

Under the Protection of Personal Information Act (Popia), companies must notify affected customers of breaches, but individuals must also act swiftly verifying breach details, updating passwords, replacing compromised cards, and enabling multi-factor authentication. However, misconceptions persist, with many believing cybercrime only affects large corporations.

Ali highlights that human error remains the weakest link, as executives and employees often lack awareness of threats like phishing and spear-phishing. Weak identity management, inadequate firewalls, and reliance on generic compliance policies further expose organizations. South Africa’s perceived weaker cybersecurity infrastructure and lighter penalties make it an attractive target for attackers.

The financial impact is severe: IBM’s 2025 report estimates the average data breach cost for South African businesses at R44.1 million far exceeding Popia’s maximum fine of R10 million. Despite this, many companies prioritize short-term revenue over cybersecurity investments, treating it as a compliance checkbox rather than a critical business risk. The growing threat underscores the need for heightened vigilance across all sectors.

Source: https://www.sowetan.co.za/news/2026-07-08-rise-in-data-breaches-puts-influencers-and-everyday-users-at-risk/

World Wide Industrial and Systems Engineers (WWISE) cybersecurity rating report: https://www.rankiteo.com/company/wwise

Information Governance with Millican & Associates cybersecurity rating report: https://www.rankiteo.com/company/information-governance

"id": "WWIINF1783520960",
"linkid": "wwise, information-governance",
"type": "Cyber Attack",
"date": "4/2025",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'location': 'South Africa',
                        'type': ['Individuals', 'Organizations']}],
 'attack_vector': ['Phishing', 'Spear-Phishing'],
 'customer_advisories': 'Affected customers must be notified of breaches under '
                        'Popia. Individuals should verify breach details, '
                        'update passwords, replace compromised cards, and '
                        'enable multi-factor authentication.',
 'data_breach': {'number_of_records_exposed': '2,374 security compromise '
                                              'notifications (2024/25), 1,947 '
                                              'breaches (April-November 2025)',
                 'personally_identifiable_information': 'Yes',
                 'type_of_data_compromised': ['Personal Data']},
 'description': 'South Africa is experiencing a sharp increase in cyber '
                'threats, with data breaches rising by 40% in recent months. '
                'Cybercriminals are increasingly targeting individuals with '
                'strong online presences, particularly social media '
                'influencers, and organizations due to weak cybersecurity '
                'infrastructure and human error.',
 'impact': {'financial_loss': 'R44.1 million (average data breach cost for '
                              'South African businesses)',
            'identity_theft_risk': 'High'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Personal data of social '
                                                    'media influencers may '
                                                    'already be circulating'},
 'lessons_learned': 'Human error is the weakest link in cybersecurity. Many '
                    'organizations underestimate cyber threats and prioritize '
                    'short-term revenue over cybersecurity investments. South '
                    "Africa's perceived weaker cybersecurity infrastructure "
                    'and lighter penalties make it an attractive target for '
                    'attackers.',
 'post_incident_analysis': {'corrective_actions': ['Improve employee training',
                                                   'Strengthen identity '
                                                   'management',
                                                   'Enhance firewall '
                                                   'protections',
                                                   'Develop tailored '
                                                   'cybersecurity policies',
                                                   'Invest in cybersecurity '
                                                   'infrastructure'],
                            'root_causes': ['Human error',
                                            'Weak identity management',
                                            'Inadequate firewalls',
                                            'Generic compliance policies',
                                            'Lack of cybersecurity awareness']},
 'recommendations': ['Verify breach details',
                     'Update passwords',
                     'Replace compromised cards',
                     'Enable multi-factor authentication',
                     'Improve identity management',
                     'Strengthen firewalls',
                     'Enhance employee awareness of phishing and '
                     'spear-phishing threats',
                     'Treat cybersecurity as a critical business risk rather '
                     'than a compliance checkbox'],
 'references': [{'source': 'Information Regulator of South Africa'},
                {'source': 'IBM 2025 Report'},
                {'source': 'WWISE (Muhammad Ali)'}],
 'regulatory_compliance': {'fines_imposed': 'Up to R10 million (maximum fine '
                                            'under Popia)',
                           'regulations_violated': ['Protection of Personal '
                                                    'Information Act (Popia)'],
                           'regulatory_notifications': 'Companies must notify '
                                                       'affected customers of '
                                                       'breaches'},
 'response': {'remediation_measures': ['Updating passwords',
                                       'Replacing compromised cards',
                                       'Enabling multi-factor authentication']},
 'title': 'Surge in Cyberattacks and Data Breaches in South Africa',
 'type': ['Data Breach'],
 'vulnerability_exploited': ['Human Error',
                             'Weak Identity Management',
                             'Inadequate Firewalls',
                             'Generic Compliance Policies']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.