DYVE|TECH Latest
News

Nigeria Records 4,975 Weekly Cyberattacks as Ransomware Victims Surge 87%

Nigeria Records 4,975 Weekly Cyberattacks as Ransomware Victims Surge 87%: Nigeria recorded an av...

Nigeria Records 4,975 Weekly Cyberattacks as Ransomware Victims Surge 87%: Nigeria recorded an average of 4,975 cyberattacks per organisation every week in J...

More from Dyve Tech →

Nigeria recorded an average of 4,975 cyberattacks per organisation every week in July, more than twice the global average, as ransomware activity surged and the growing use of generative AI introduced another avenue for sensitive data exposure.

The figures are contained in the latest Global Threat Intelligence insights from Check Point Research, the threat intelligence arm of Check Point Software Technologies.

Globally, organisations experienced an average of 2,336 cyberattacks per week in July, representing a 3% increase from June and a 16% increase compared with July 2025.

Africa recorded a substantially higher average of 3,237 attacks per organisation per week, placing the continent among the world’s most heavily targeted regions. Latin America recorded the highest regional average at 3,561, followed by Asia-Pacific at 3,316. (Novus Press Bulletin)

Within Africa, Angola recorded the highest attack rate at 5,714 per organisation per week, followed by Nigeria at 4,975, Kenya at 2,915 and South Africa at 2,195.

Nigeria’s figure was therefore more than double the global average and significantly above the wider African average. (Novus Press Bulletin)

Financial Services, Government, and Energy and Utilities were the three most targeted sectors in Africa during the month.

Nigeria’s cyber threat exposure remains exceptionally high

The July figures continue a pattern in which Nigerian organisations have consistently appeared among the most heavily targeted organisations in Check Point’s monthly regional data.

The scale of the July figure is particularly notable when compared with the global baseline. An organisation represented in Check Point’s Nigerian sample faced an average of 4,975 attack attempts per week, compared with 2,336 globally.

That does not mean every Nigerian organisation experienced 4,975 successful breaches. The metric measures observed cyberattack activity against organisations and should be understood as an indicator of attack pressure rather than a count of confirmed compromises.

The distinction matters because high attack volume does not automatically translate into successful intrusions. It does, however, indicate the intensity of activity security teams are required to detect, investigate and block.

Check Point Regional Director for Africa Lorna Hardie said the July figures showed that organisations were increasingly dealing with multiple forms of cyber risk simultaneously.

“July’s data shows that cyber risk is accumulating across multiple fronts at once,” Hardie said. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity.”

She said organisations needed prevention-focused security capable of protecting networks, users, data and AI workflows before attacks cause damage. (Novus Press Bulletin)

Education remains the world’s most targeted sector

Education recorded the highest attack volume among industries globally in July.

Organisations in the sector faced an average of 4,848 attacks per week, a 14% increase from the same period in 2025.

Government organisations followed with 3,044 attacks per week, while Telecommunications recorded 2,927.

Energy and Utilities recorded 2,759 weekly attacks, representing a 20% year-on-year increase.

Hospitality, Travel and Recreation rounded out the global top five with 2,614 attacks per organisation per week, up 28% year on year. (Novus Press Bulletin)

The figures underline how attackers are continuing to target sectors that combine large volumes of sensitive information with complex, highly distributed technology environments.

Education, for example, can provide access to student and staff records, research data, financial information and large numbers of user accounts. Government and telecommunications organisations similarly operate large digital infrastructures that can offer significant value to attackers.

GenAI is creating a new path for data leakage

The threat picture is no longer limited to attackers attempting to break into corporate systems.

Employees’ use of generative AI tools is creating another potential route for sensitive information to leave organisations.

Check Point found that one in every 36 enterprise prompts analysed carried a high risk of sensitive-data leakage.

Among organisations regularly using GenAI tools, 88% had users submitting high-risk prompts, while approximately 22% of prompts contained potentially sensitive information. (Novus Press Bulletin)

The scale of adoption is also significant.

Organisations used an average of eight GenAI tools, while users generated approximately 95 prompts each.

Personal information was the most commonly exposed category, appearing in 70% of organisations examined. Financial information and network or IT infrastructure information each appeared in 68%. (Novus Press Bulletin)

The risk is therefore not necessarily an employee deliberately attempting to leak company information.

A user could paste source code into an AI assistant for debugging, submit internal financial information while requesting an analysis, or provide customer information while asking an AI system to summarise a document.

If an organisation does not have appropriate controls around enterprise AI usage, legitimate productivity workflows can become an unintentional data-exfiltration channel.

Phishing remains a major route into organisations

Email also remained a significant attack vector in July.

Check Point classified one in every 128 emails, or 0.78% of examined messages, as phishing.

Another 20% fell into unwanted or risky categories, including spam, graymail and suspicious messages. (Novus Press Bulletin)

Africa recorded the highest phishing rate among the regions measured, with approximately one in every 106 emails classified as phishing. North America followed at one in every 117.

Phishing campaigns can be used to steal credentials, deliver malware, establish initial access to corporate networks or facilitate business email compromise.

The continued prevalence of phishing is significant because it demonstrates that attackers do not necessarily need a sophisticated technical exploit to gain access. A convincing message and a compromised or careless user can provide an effective entry point.

Ransomware activity jumps 87% year on year

The sharpest movement in the July data came from ransomware.

Check Point recorded 964 reported ransomware victims during July, representing a 49% increase from June and an 87% increase from July 2025.

The July figure also marked a significant departure from the pattern observed during the first half of 2026, when monthly ransomware activity averaged about 672 reported incidents. (Novus Press Bulletin)

Business Services accounted for the largest share of reported ransomware victims at 32.5%.

Industrial Manufacturing followed at 14.4%, while Consumer Goods and Services accounted for 13.4%.

Geographically, North America represented 45% of reported ransomware incidents, followed by Europe at 28% and APAC at 17%.

The United States alone accounted for 39.4% of reported victims, ahead of Germany, Canada, the United Kingdom and Italy. (Novus Press Bulletin)

The data is based on reported ransomware victims, meaning it represents publicly identified incidents rather than the full universe of ransomware activity. Undisclosed attacks and incidents that never become public are not necessarily captured.

The Gentlemen and Qilin lead July ransomware activity

The ransomware ecosystem remained fragmented in July, with several groups accounting for significant portions of published victim activity.

The Gentlemen and Qilin were the two most prevalent groups, each accounting for 14% of published ransomware attacks.

DeadLock ranked third at 10%, with 97 reported victims. (Novus Press Bulletin)

The distribution illustrates the continuing fluidity of the ransomware ecosystem. Groups can rise rapidly in published victim counts while affiliates, infrastructure and operating models change.

For organisations, that makes defending against ransomware based solely on tracking individual groups increasingly difficult.

What the July numbers mean for Nigerian organisations

The most important finding from the July data is not simply that Nigeria recorded nearly 5,000 attacks per organisation each week.

It is that several risk channels are increasing or remaining persistent at the same time.

Nigerian organisations are facing high attack volumes while also operating in an environment where phishing remains a practical route for credential theft, ransomware activity is accelerating globally, and employees are increasingly interacting with AI systems that can process sensitive business information.

That combination changes the security equation.

Traditional perimeter protection remains necessary, but organisations also need stronger identity controls, endpoint protection, email security, data-loss prevention, AI-use governance, vulnerability management and rapid incident response.

The GenAI findings add another requirement: organisations need to know which AI tools employees are using, what information is being submitted to them, and what controls exist around that activity.

For Nigerian businesses undergoing rapid digitalisation, the July figures provide a clear warning. Expanding digital infrastructure also expands the number of systems, identities, applications and data flows that attackers can target.

The challenge is therefore not simply reducing the number of attacks reaching an organisation.

It is ensuring that when those attacks arrive, they do not become breaches.


Source: Check Point Research, Global Threat Intelligence insights for July 2026. The July release was issued on August 13, 2026. (Novus Press Bulletin)