Surge in DDoS Attacks Targeting South African ISPs

Surge in DDoS Attacks Targeting South African ISPs

First seen 20 May 2026, 15:26 UTC Itweb.Co.ZaThecondiaM.Engineeringnews.Co.ZaEngineeringnews.Co.ZaTech.Africa+1 82% similarity 51.9

Article Content

Browse articles
ThreatCluster

South African ISPs, including 1-Grid and Seacom, are facing large-scale DDoS attacks that have disrupted services. The attacks are characterized by low ransom demands, suggesting a rise in cheap DDoS tools on the dark web. 1-Grid reported intermittent service disruptions due to these attacks, while Seacom confirmed targeted malicious traffic affecting its network. Network Platforms noted a decrease in attack activity but warned of potential recurrence as they did not comply with ransom demands. Experts believe these attacks may not be financially motivated but could be a smokescreen for mapping network dependencies. The situation remains dynamic, with ongoing mitigation efforts by affected ISPs.

Key Points: • South African ISPs are experiencing large-scale DDoS attacks, impacting service availability. • Ransom demands from attackers are unusually low, indicating a possible shift in attack motivations. • Mitigation efforts are ongoing, but ISPs warn of potential for continued or recurring attacks.

ThreatCluster AI

Timeline

2026-05-18
1-Grid hit by large-scale DDoS attack
1-Grid experienced service disruptions due to a large-scale DDoS attack, affecting parts of its infrastructure.
Itweb.Co.Za
2026-05-20
Seacom confirms DDoS disruption
Seacom reported a high-volume DDoS incident causing temporary network impacts, confirmed as malicious traffic.
Itweb.Co.Za
2026-05-20
Network Platforms reports reduced attack activity
Network Platforms noted a significant reduction in attack activity but warned of possible future attacks due to ransom demands.
Itweb.Co.Za

Community

Browse all →