Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Symbolic ceremony celebrates shared Olympic heritage

    June 30, 2025

    Mr Chow brings a slice of London snobiety meets Dubai bling

    June 30, 2025

    Ramaphosa defends equity alternatives for BEE

    June 30, 2025
    Facebook X (Twitter) Instagram
    • Home
    • Contact Us
    • About Us
    • Privacy Policy
    • Terms Of Service
    • Advertisement
    Monday, June 30
    Facebook X (Twitter) Instagram Pinterest Vimeo
    ABSA Africa TV
    • Breaking News
    • Africa News
    • World News
    • Editorial
    • Environ/Climate
    • More
      • Cameroon
      • Ambazonia
      • Politics
      • Culture
      • Travel
      • Sports
      • Technology
      • AfroSingles
    • Donate
    ABSLive
    ABSA Africa TV
    Home»Technology»ITWeb TV: Data exfiltration overtakes ransomware attacks in SA
    Technology

    ITWeb TV: Data exfiltration overtakes ransomware attacks in SA

    Chris AnuBy Chris AnuApril 12, 2025No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    ITWeb TV: Data exfiltration overtakes ransomware attacks in SA
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Expert digital forensics auditor professor Danny Myburgh, MD of Cyanre, provides an overview of the latest cyber crime trends he’s seeing being committed in South Africa. He also details some of the cases he’s worked on and the entry paths and skills needed to get into the field of digital forensics.

    Ransomware attacks are on the decline, and are being replaced by data exfiltration, says an expert local digital forensics auditor.

    Professor Danny Myburgh, MD of Cyanre, speaking to ITWeb TV, said his company is called to handle 40 to 60 major breaches of large South African companies every year and has noted a decrease in ransomware in recent months.

    This, he surmised, is due to companies adopting better backup and recovery strategies, including air-gapping.

    “Data exfiltration attacks have more or less doubled, as opposed to ransomware attacks. Last year, we saw double extortion, where they encrypt your data and steal it; we’re still seeing that but it’s as if [most of] the hackers aren’t even going to that extent anymore, in terms of encrypting the information, so the exfiltration attacks are really picking up.”

    Myburgh added that data exfiltration attacks are about 10 times more costly to investigate and remediate, as they involve lawyers, notifying the data subjects, and are harder to pinpoint when the attackers gained access to the environment.

    Professor Danny Myburgh, MD of Cyanre.


    He also revealed that attackers are using artificial intelligence (AI), which is helping them to reduce the time they are in a hacked environment.

    “While the victims and clients are using AI to increase or improve their security, hackers are also [using] it. IBM found last year that the average time a hacker is in an environment is 209 days. We found on all the breaches we handled that it came down to about 170 days and it’s because they are automating their attacks.”

    The sophistication of the attacks is also increasing, he noted, whereby they are learning how to work around multifactor authentication.

    “We have seen a number [of cases] where the hackers would attack the cookie structure; for example, the tokens that are issued and they keep those tokens alive, therefore they have access up to 30 days into that environment without having to do a second two-factor authentication.”

    For companies that have been breached, Myburgh’s advice is for those with an internal IT team to not be too hasty in terms of fixing the problem, as a hacked server is a crime scene.

    “The whole objective of an IT team is to make the problem go away, fix the problem, get the networks to work; that’s why management is screaming at them. If you don’t conduct an investigation of exactly what happened, you might be living under a situation where you won’t know what the hackers did, what they took out, what backdoors they have in the environment.

    “We conducted two investigations in the past year where we saw that the hackers, before encrypting the environment, went into the financial system, and we couldn’t figure out why. After we decrypted the information for the client, we advised them that we saw this access. The client did an analysis and we found in both instances that they were making quite large yearly licensing fee payments to America, for a couple of million rand, and that the hackers had changed the banking details on the system.”

    Myburgh advised companies that don’t have an internal IT capacity to not 100% trust their external IT service provider.

    “In more than 9% of our matters, the IT service provider is responsible for the breach. Either it’s one of their personnel using that environment for cryptojacking, for example, or where the hack came through them. We had one case, for example, where the IT consultant’s laptop was compromised, and he used the same password for all clients.”

    He also recounted two cases where the external service provider claimed the firewall was up to date, but when the investigation took place, it was found that the firewall update happened after the breach, and the firewall was the cause of the breach.

    Digital forensics skills gap

    Myburgh also outlined that the digital forensic audit space in South Africa is heavily lacking skills.

    “The field actually is very understaffed in South Africa. It’s one of the areas where we’ve got critical scarcities in these skills. The president, in his State of the Nation Address, mentioned that the NPA [National Prosecuting Authority] is actively busy with a project to build a digital forensic lab, and some of those efforts are to look at local resources, as well as international resources, to staff it.”

    He added that, by his estimates, there are less than 100 digital forensic practitioners in South Africa, and less than 20 are of high enough standing to be considered expert witnesses capable of testifying in courts.

    International companies can also offer remote employment opportunities with better pay, which is a challenge for the local sector.

    The field is unusual in that it requires a mixture of IT skills and the ability to conduct investigations. “We recruit quite a lot of candidates that have a BSc computer science degree. They can also specialise in cyber security.”



    Source link

    Post Views: 8
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Chris Anu
    • Website

    Related Posts

    Ramaphosa defends equity alternatives for BEE

    June 30, 2025

    Trend Micro, Dell, NVIDIA partner on AI-powered cyber security

    June 30, 2025

    Starlink eyes South Africa licence with R2-billion investment pledge

    June 30, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Who is Duma Boko, Botswana’s new President?

    November 6, 2024

    As African Leaders Gather in Addis Ababa to Pick a New Chairperson, They are Reminded That it is Time For a Leadership That Represents True Pan-Africanism

    January 19, 2025

    BREAKING NEWS: Tapang Ivo Files Federal Lawsuit Against Nsahlai Law Firm for Defamation, Seeks $100K in Damages

    March 14, 2025

    Kamto Not Qualified for 2025 Presidential Elections on Technicality Reasons, Despite Declaration of Candidacy

    January 18, 2025
    Don't Miss

    Symbolic ceremony celebrates shared Olympic heritage

    By Prudence MakogeJune 30, 2025

    The South African Sports Confederation, Olympic and Paralympic Committee (SASCOC) and the Greek Embassy in…

    Your Poster Your Poster

    Mr Chow brings a slice of London snobiety meets Dubai bling

    June 30, 2025

    Ramaphosa defends equity alternatives for BEE

    June 30, 2025

    Connecticut Towing Reforms Will Help Some but Not All, Drivers Say — ProPublica

    June 30, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Sign up and get the latest breaking ABS Africa news before others get it.

    About Us
    About Us

    ABS TV, the first pan-African news channel broadcasting 24/7 from the diaspora, is a groundbreaking platform that bridges Africa with the rest of the world.

    We're accepting new partnerships right now.

    Address: 9894 Bissonette St, Houston TX. USA, 77036
    Contact: +1346-504-3666

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Symbolic ceremony celebrates shared Olympic heritage

    June 30, 2025

    Mr Chow brings a slice of London snobiety meets Dubai bling

    June 30, 2025

    Ramaphosa defends equity alternatives for BEE

    June 30, 2025
    Most Popular

    Symbolic ceremony celebrates shared Olympic heritage

    June 30, 2025

    Did Paul Biya Actually Return to Cameroon on Monday? The Suspicion Behind the Footage

    October 23, 2024

    Surrender 1.9B CFA and Get Your D.O’: Pirates Tell Cameroon Gov’t

    October 23, 2024
    Facebook X (Twitter) Instagram Pinterest YouTube
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    © 2025 Absa Africa TV. All right reserved by absafricatv.

    Type above and press Enter to search. Press Esc to cancel.