Should South Africa ban ransomware payments?

Should South Africa ban ransomware payments?


Richard Firth has paid a ransom and seen what it bought. Now the MIP Holdings CEO wants South Africa to outlaw such payments. “I think banning ransomware payments will be a powerful deterrent,” Firth told TechCentral on Tuesday.

MIP, which supplies software to insurers, paid cybercrime group The Gentlemen a sum Firth described as “substantial” after the gang stole data on customers of about 45 insurers earlier this year. Firth stressed that the attackers reached not MIP’s administration platforms but “a third-party tool that we use for support ticket management” – an Atlassian Jira service MIP was already replacing, as TechCentral has reported.

The gang undertook to destroy the data if paid. It appears it did not and earlier this month had turned on the attacked insurers. Hollard, which refused a ransom demand of its own, saw client data published on the dark web. Hollard said its forensic work found “no evidence of compromise within the Hollard environment” and linked the leak to the MIP incident.

Firth sees cryptocurrency as the catalyst. “There is so much being said about the government trying to ban crypto payments across borders through the Reserve Bank’s draft regulations. But I don’t think crypto is currently truly being regulated at all and that leaves this massive gaping hole for attackers,” he said. “I think by closing the catalyst, the payment cycle stops and there is no more incentive to do it.”

The draft crypto asset manual published by national treasury and the Reserve Bank in August would bar South African companies from cross-border crypto transactions in either direction. In effect, it would do for companies much of what Firth is asking for. Yet a coalition of crypto platforms, now joined by GoTyme Bank, is fighting the rules.

“Before making the ransom payment, we did a ‘terrorist check’ on the accounts given, and they came back green for anti-money laundering tests, even though it is a ransom payment,” Firth said. “We develop software platforms, so we have all the ISO certifications and everything in place, and it meant nothing. So, no one is safe. The [payments] mechanism isn’t being controlled at all.”

‘Absolutely rampant’

He said attacks are widespread and victims often keep quiet. “It is absolutely rampant at the moment out there in terms of ransomware attacks in South Africa; there are hundreds of attacks every month. But people are staying quiet. People don’t want to admit when they’ve been attacked.”

Dominic White, MD for South Africa at Orange Cyberdefense, is less sure about banning the payment of ransoms. “I think there’s two legitimate sides to this debate and the trick is reconciling them,” he said. “Blindly banning ransomware payments doesn’t alleviate the pressure that causes a victim to pay in the first place.”

If the aim is fewer payments, he said, “we need to design an intervention that changes victim behaviour and improves the chances of recovery, rather than adding a criminal penalty at the worst moment in a victim’s crisis”.

He pointed to the UK. Its options assessment accepts that victims “should be able to pay as a last resort”. The British home office (that country’s equivalent of South Africa’s department of home affairs) instead confirmed it would ban payments only by public sector bodies and operators of critical national infrastructure, a choice White said was made “as much in the hopes of reducing it as a target as preventing public funds being sent to criminals”. It has yet to become law.

White is more taken with Australia’s approach, where since 30 May 2025 businesses with turnover above A$3-million and operators of critical infrastructure have had to report any ransom payment within 72 hours. That approach, he said, makes “a move for visibility first before deciding on further regulation”.

MIP Holdings CEO Richard Firth
MIP Holdings CEO Richard Firth

Australia deferred a ban rather than dropping the idea. Then home affairs minister Clare O’Neil told ABC RN in November 2023 that it was “clearly not the right time at this moment to ban ransoms”, but that “everyone who I work with accepts that a ban at some stage is inevitable”.

“I think what’s missing, and where South Africa could innovate, is on the incentive side,” White said. “Instead of paying ransoms to criminals, government could make paying towards recovery significantly more attractive: tax relief, rebates, grants for smaller organisations, or perhaps cyber-recovery funding could be conditional on prompt reporting to law enforcement and using appropriately accredited incident-response providers.”

That, he said, “gives government better intelligence, directs money into remediation rather than organised crime, and leaves the victim with a more valuable outcome in the long term”.

Any ban should also have what he calls a break-glass mechanism: a victim that had reported the attack and hired an accredited responder could apply for a fast-tracked exception, showing that other routes to recovery were exhausted and paying was the only option, for the authorities to approve.

North Carolina became the first US state to outlaw ransom payments by public bodies, in a law enacted on 18 November 2021. Nearly a year later, state CIO Jim Weaver told The Charlotte Observer that it was “too early to tell” whether the ban would deter attacks. State figures cited in the same report showed attacks on public bodies in 2022 up on 2021, though below a peak of 17 incidents in 2020.

Brett Callow, at the time a threat analyst at Emsisoft, told Cybersecurity Dive in April 2024 that “state-level bans do not necessarily reduce the number of attacks”, but that attackers “absolutely would be aware of a federal-level ban that applied nationally”.

‘Deterrent effect may be limited’

Fabian Teichmann of the London School of Economics, in a recent paper, wrote that “early evidence from North Carolina suggests the deterrent effect may be limited”, though he still backs harmonised bans for governments and critical infrastructure as part of a wider package.

Fewer victims are paying, even without bans, but attacks have not fallen. Chainalysis estimates that ransomware payments fell 8% to US$820-million in 2025. The share of victims paying may have reached an all-time low of 28%, while claimed victims rose by 50%, according to leak-site data it cites.

South Africa signed a November 2023 statement by members of the International Counter Ransomware Initiative agreeing that “relevant institutions under the authority of our national government should not pay ransomware extortion demands”. The pledge carries no legal force, and its commitment covers only state institutions.

Section 54 of the Cybercrimes Act, which would require communications providers and financial institutions to tell the police when their service or network is involved in certain offences, still awaits proclamation, according to law firm MJ Kotze Inc. Popia already requires breach notices, and insurers must report material incidents to the Prudential Authority within 24 hours under Joint Standard 2 of 2024, the PA told TechCentral.

Orange Cyberdefense's Dominic White
Orange Cyberdefense’s Dominic White

Sophos’s State of Ransomware in South Africa 2026, released this month, surveyed 135 local organisations hit in the past year. Of those whose data was encrypted, 58% paid a ransom to recover it, down from 71% a year earlier, while 54% used backups, up from 35%.

The same survey shows how exposed local organisations are. Only 40% of local victims recovered within a week, the lowest rate of any country surveyed, and 47% cited a lack of protection as an operational root cause, the highest of any country. Without an exception like White’s break-glass mechanism, a ban would take the option of paying away from organisations in that position.  — © 2026 NewsCentral Media