24/07/2026
Cybersecurity threats increase by almost 40% in second quarter of 2026
Staff Reporter
IN a mere three-month period from April to June 2026, Namibia is said to have been exposed to a total of 513,921 cybersecurity vulnerabilities, a 39.8% increase compared to the same period last year.
Cyber events also increased by 56.7%, with 161,547 events detected during the reporting period.
Following this unprecedented increase, the Namibia Cyber Security Incident Response Team (NAM-CSIRT), housed under the Communications Regulatory Authority of Namibia (CRAN), has highlighted the need for organisations to strengthen their cybersecurity measures and remain vigilant against evolving cyber threats.
Mufaro Nesongano, CRAN media liaison officer, said that the increase in vulnerabilities was largely driven by continued exposure to remote management and legacy network services.
The cybersecurity landscape was further characterised by emerging ransomware and extortion threats, including BAVACAI ransomware and the Black X cybercriminal extortion group. BAVACAI, identified in May, involves a double-extortion approach involving the theft and encryption of sensitive data, while Black X has been associated with data theft and extortion targeting organisations holding high-value and sensitive information.
Nesongano also said that, in a significant development during the quarter, Namibia launched the National Cybersecurity Incident Management Guidelines 2026.
Officially launched by the Minister of Information and Communication Technology, Emma Theofelus, on 29 April 2026 in Ondangwa, the Guidelines provide a practical framework for strengthening the detection, reporting, response and coordination of cybersecurity incidents across sectors.
The Guidelines further promote a proactive, risk-based approach to cybersecurity and align with international standards, including ISO/IEC 27001 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework. They are intended to support stronger collaboration among government institutions, regulators, operators of critical systems, industry and the broader cybersecurity community.
Emilia Nghikembua, CRAN’s Chief Executive Officer and Head of NAM-CSIRT, emphasised that the increase in cyber vulnerabilities and events during the second quarter is a reminder that cybersecurity threats remain persistent and continue to evolve. While these figures highlight areas that require urgent attention, they also provide valuable insight into where organisations can strengthen their security posture.
“It is important that organisations take proactive steps to address exposed services, protect digital identities, apply security updates timeously and report incidents early,” stated Nghikembua.
She added that the launch of the National Cybersecurity Incident Management Guidelines 2026 is an important step in strengthening Namibia's collective ability to manage cyber incidents.
“However, the effectiveness of these Guidelines will depend on their adoption and implementation across sectors. Cybersecurity is a shared responsibility, and through collaboration, information sharing and coordinated response, we can build a more secure and resilient digital ecosystem for Namibia,” Nghikembua said.
She stated that, in conclusion, organisations and individuals are encouraged to adopt good cybersecurity practices, including the use of strong and unique passwords, regular password updates, multi-factor authentication, timely software updates, secure configuration of internet-facing systems and heightened awareness of phishing and other social engineering attacks.
Picture for illustrative purposes only. Photo: Contributed