Cyberattacks Hit 82% of META SMBs as Password-Stealer Threats Surge 51% in Africa

Cyberattacks on African SMBs rise as Kaspersky reports growing threats across Africa
Image credit: Kaspersky

Cyberattacks on African SMBs are becoming a growing business risk, as new Kaspersky research shows that 82% of small and mid-sized businesses across the Middle East, Türkiye and Africa encountered at least one cybersecurity incident over the past year.

The findings, released alongside GITEX Nigeria 2026, suggest that smaller companies can no longer assume they are less attractive targets than large enterprises.

According to Kaspersky, only 18% of small and medium-sized businesses (SMBs) surveyed in the Middle East, Türkiye and Africa (META) region avoided a cybersecurity incident during the past year. Globally, the equivalent figure among businesses with 100 to 499 employees was 14%.

The research comes as African businesses deepen their reliance on cloud platforms, remote access, digital payments, artificial intelligence and other connected technologies, expanding their potential exposure to cybercrime at the same time.

Cyberattacks on African SMBs are becoming more sophisticated

Some of the most significant increases reported by Kaspersky involve malware designed to gain access to corporate systems, credentials and sensitive information.

Across Africa, detections of password-stealing malware increased by 51% over the period covered by Kaspersky’s latest statistics, while backdoor detections rose by 23% and spyware detections increased by 16%.

Password stealers are particularly significant for businesses because compromised credentials can provide attackers with an entry point into email accounts, cloud services, financial systems and other corporate platforms.

Backdoors, meanwhile, can allow attackers to maintain persistent access to an infected environment, while spyware may be used to collect confidential business information.

The rise in cyberattacks on African SMBs is particularly significant as smaller companies accelerate their use of digital services while often operating with fewer cybersecurity resources than larger enterprises.

Nigeria records millions of attempted attacks

Nigeria provides a particularly clear example of the scale of the cybersecurity challenge facing African businesses.

Kaspersky said its security technologies blocked more than 1.6 million online attack attempts targeting users in Nigeria during the first half of 2026.

These included threats involving password stealers, spyware, exploits and other forms of malicious activity.

A further 2.5 million on-device threats were blocked in Nigeria during the same period, according to Kaspersky.

Such threats can include malware delivered through infected USB drives and other files reaching devices outside conventional web-based attack channels.

The figures underline the scale of the challenge facing businesses as Nigeria’s economy becomes increasingly dependent on digital platforms, connected business systems and online services.

Phishing remains one of the biggest SMB risks

Kaspersky’s latest survey covered 1,800 IT security specialists across SMBs and larger enterprises in 18 countries.

On average, organisations experienced three different types of security incidents during the previous year.

Among SMBs globally, phishing was the most commonly reported category, affecting 20% of organisations surveyed.

Exploitation of software vulnerabilities followed at 17%, while incidents involving external remote access affected 16%.

Within the META region, phishing and software vulnerability exploitation were each reported by 19% of SMBs.

The use of weak or stolen credentials affected 18%, while 16% reported incidents associated with external remote access.

Although zero-day exploits and trusted relationship attacks ranked lower, Kaspersky said each category was still experienced by 8% of organisations surveyed.

This suggests that businesses face a broad range of risks rather than a single dominant form of cyberattack.

People and security policies remain major vulnerabilities

The research also highlights cybersecurity challenges that cannot be addressed simply by purchasing additional security software.

Among META SMBs, 25% of respondents identified insufficient cybersecurity expertise among IT staff as one of the factors increasing the likelihood of successful attacks.

An equal 25% pointed to inadequate IT security policies.

High workloads within IT security departments were identified by 24%, while 23% cited insufficient centralised control over IT infrastructure and shadow IT.

A further 22% pointed to inadequate cybersecurity awareness among employees.

The same proportion identified business decisions made without sufficient consideration of IT security as another important risk.

The figures underline the growing importance of cybersecurity as a management issue rather than solely an IT function.

For smaller African businesses in particular, rapid digitalisation can create new vulnerabilities when technology adoption moves faster than security governance, employee training and access controls.

Cybersecurity budgets are rising

Businesses appear to be responding to these pressures by allocating more resources to cybersecurity.

Globally, 75% of SMBs surveyed said they had increased their cybersecurity budgets this year.

In the META region, the proportion was 70%.

Meanwhile, 69% of SMBs in META said they planned to strengthen their IT security function.

Some 36% allocated additional funding to expand their IT and cybersecurity teams, while 32% invested additional budget in IT security training for employees.

Another 24% allocated additional resources to advanced security technologies such as extended detection and response (XDR), network detection and response (NDR) and security information and event management (SIEM).

The spending patterns suggest that cybersecurity is moving higher on the investment agenda of growth-stage businesses across the region.

Skills shortages add to the challenge

Ilya Markelov, Head of Unified Platform Product Line at Kaspersky, said companies of all sizes can now be targeted using sophisticated attack methods.

“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture.”

Markelov said growing companies are frequently constrained by limited budgets and the global shortage of information-security specialists.

This creates a particular challenge for SMBs, which need to strengthen protection without necessarily being able to build the large internal cybersecurity teams available to major corporations.

The issue therefore extends beyond acquiring security technology. Companies also need appropriate internal policies, employee awareness, access controls and processes for managing incidents when they occur.

AI and digitalisation expand the attack surface

Artificial intelligence and other emerging technologies are adding another dimension to the cybersecurity challenge.

As businesses experiment with generative AI, cloud applications and new digital productivity platforms, employees may adopt services before they have been formally assessed or approved by corporate IT teams.

This can contribute to shadow IT — one of the risk factors identified by respondents in Kaspersky’s META research.

For smaller businesses, the challenge is to benefit from faster digital adoption without allowing uncontrolled applications, weak credentials or poorly managed access rights to undermine security.

Cybersecurity therefore needs to develop alongside digital transformation rather than being introduced only after new technologies have already been deployed.

Cybersecurity becomes a business issue

The implications extend beyond IT departments.

A cyber incident can affect payment systems, customer information, supplier relationships, communications and business continuity.

For SMEs operating with limited financial and operational reserves, even a relatively short disruption can have significant commercial consequences.

At the same time, compromised customer or corporate data can damage trust and potentially expose companies to regulatory and legal risks.

Addressing cyberattacks on African SMBs will therefore increasingly require companies to combine technology investment with stronger internal policies, staff training and tighter control over digital access.

GITEX Nigeria puts cybersecurity in focus

The findings were released in connection with GITEX Nigeria 2026, taking place from 31 August to 3 September.

The event brings together technology companies, startups, investors, policymakers and business leaders as Nigeria seeks to strengthen its position in Africa’s rapidly expanding digital economy.

Cybersecurity is becoming increasingly important within that wider transformation as businesses adopt artificial intelligence, cloud computing, digital payments and other connected technologies.

For African businesses, the Kaspersky findings point to a broader consequence of digitalisation: the more deeply organisations depend on digital infrastructure, the less realistic it becomes to treat cybersecurity as an optional expense.

For SMBs in particular, the issue is increasingly tied not only to protecting data but also to maintaining business continuity, safeguarding financial systems and retaining customer trust.

Sources and Information

Additional survey, Africa and Nigeria-specific statistics were provided by Kaspersky in material supplied to AfricaBusiness.com on 31 August 2026.