
Ransomware remains one of the most significant cyber threats globally in May, with 698 publicly reported attacks, representing a 48% increase year on year — the sharpest annual increase recorded in 2026.
Government and Critical Infrastructure Face Concentrated PressureGlobally, Government ranked as the second most targeted sector in May, experiencing an average of 2,620 weekly attacks per organisation, while Telecommunications ranked third with 2,583 weekly attacks.
In Africa, this pressure was particularly visible in attacks targeting government services and national infrastructure. Government and public-service portals, particularly in Egypt, experienced coordinated disruption campaigns linked to hacktivist-aligned actors seeking both political visibility and operational impact. In South Africa, several prominent Government institutions were reportedly breached, including the South African Revenue Service (SARS), SITA, and the City of Ekurhuleni.
Telecommunications providers were also targeted during the same campaign cycle, demonstrating how threat actors increasingly focus on interconnected public infrastructure. The concentration of attacks against government institutions, financial services, and telecommunications within a single geography underscores the continued attractiveness of high-visibility national infrastructure as a target.
Education Remains the Most Targeted Industry Worldwide
The Education sector once again ranked as the most attacked industry globally, facing an average of 4,641 weekly attacks per organisation, a 7% increase year on year.
Educational institutions continue to present attractive targets due to large user populations, open digital environments, and often constrained cyber security resources. Beyond Education, notable increases were also recorded across Agriculture, Hospitality, Travel and Recreation, and Construction and Engineering, demonstrating how digital transformation is expanding the cyber attack surface across a growing range of industries.
Perimeter Vulnerabilities Continue to Fuel Intrusions
The May findings also highlighted growing exploitation of perimeter vulnerabilities, including authentication bypass flaws affecting widely deployed VPN and firewall technologies. These vulnerabilities provide attackers with trusted access into enterprise environments and increasingly serve as entry points for ransomware operations. Once inside, threat actors can move laterally, steal credentials, and deploy ransomware or data theft operations with greater speed and efficiency.
“For many organisations across Africa that are still strengthening cyber resilience capabilities, unpatched perimeter systems remain one of the most significant sources of exposure,” de Bruin says
GenAI Adoption Creates New Exposure Risks
Check Point Research found that one in every 25 GenAI prompts submitted from enterprise environments posed a high risk of sensitive data leakage during May, affecting 91% of organisations actively using GenAI tools. An additional 22% of prompts contained potentially sensitive information. Organisations used an average of nine different GenAI applications during the month, while the typical enterprise user generated approximately 70 prompts.
Looking AheadMay’s lower attack volumes should not be interpreted as a reduction in cyber risk. Instead, the data points to a threat landscape undergoing strategic reorganisation.
“For African organisations, the findings reinforce the need to prioritise proactive security strategies focused on prevention, vulnerability management, ransomware resilience, and governance around emerging AI technologies. The numbers may have been quieter in May, but the underlying risk environment remains firmly elevated,” de Bruin concludes.
