Desk live·
ForensicPost
Breaches/Analysis/File 25-1123

African Data Protection Regimes Made 2025 Incidents Harder to Conceal

Reporting on 2025 describes African cyber incidents becoming harder to conceal as data protection regimes took effect. It is the clearest natural experiment the corpus has.

Constructed geometry · not a chart of case data
TargetAfrican disclosure regimes
ActorRegulator
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Reporting on 2025 describes cyber incidents across African jurisdictions becoming markedly harder to conceal, attributing the change to data protection regimes and regulators beginning to require and publish disclosure.

This Is The Corpus’s Central Argument, Tested

This desk has argued repeatedly that the incident record is a product of disclosure law rather than of incidence: the four filters at 25-0502, the healthcare register at 25-0630, the global aggregation problem at 25-1214, and the inversion at 25-1221.

Every one of those was an argument from structure. This file is the same claim observed as a change over time: a region introduces disclosure requirements, and incidents appear in the record. Nothing about the underlying activity needs to have changed.

And It Predicts The Statistics Will Look Worse

The scam figure at 25-0821 and the growth numbers throughout this section should be read against it. A region that starts measuring will show dramatic rises, be described as a growing threat centre, and appear in rankings of the kind this desk criticised at 25-1117.

The consequences are commercial: insurance pricing, supplier due diligence, investment risk assessment. Jurisdictions are penalised in those processes for the act of becoming transparent, which is a straightforwardly bad incentive.

What Follows For The Rest Of This Database

Every regional comparison in this corpus should be read as comparing regimes. The 62% of Asia-Pacific incidents in five countries at 25-1206, the US telecom count at 25-0718, the Latin American ranking at 25-1117 — all of them.

And the corpus should expect its own African coverage to grow substantially over coming years without that reflecting any change in what happens there. Graded medium: the observation is well described in regional reporting, and this desk has no before-and-after dataset to quantify it.

This is an analysis file

Built on published regional reporting, listed below, read against the measurement files in this database. No quantified before-and-after comparison is available. Corrections: corrections@forensicpost.com.

Sources
  1. In 2025, regulation forced Africa’s cyber incidents into the openTechCabal
  2. Africa’s cybersecurity attacks outpace prevention as damage becomes harder to hideSecurity Africa Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary