Features

INTERPOL flags cyber threats for Botswana

On the prowl: Cybercriminals are hunting down both institutions and individuals in the country
 
On the prowl: Cybercriminals are hunting down both institutions and individuals in the country

Itumeleng Garebatshabe, a veteran tech entrepreneur, software engineer and cybersecurity expert, has a troubling perspective on why many in the country continue to be hit by various forms of cyberattacks and scams.

It’s not just about more technologically advanced, sophisticated criminals bypassing the country’s guardrails and “hacking” into sensitive entities and citizens’ privacy. His experience shows that quite often, the issue is more about simple vigilance.

“One of the most striking discoveries has been how little many people know about protecting themselves online,” he said. “Simple practices such as creating strong passwords, using different passwords for different accounts or enabling two-factor authentication are completely new concepts to many participants. “Others are surprised to learn how easily criminals can impersonate trusted organisations through fake calls, messages and social media profiles.”

Garebatshabe’s findings come as Interpol shares its latest African Cyberthreat Assessment report. The report indicates that in 2025, Botswana was one of the top 10 countries hit by botnets, accounting for 1.34 percent of total attacks across the continent or 2.3 million detections.

Botnets are infected machines controlled by cybercriminals due to malware and can be a prime delivery mechanism of ransomware. Ransomware, on the other hand, is malicious software that locks or encrypts a victim’s data and demands payment to restore access.

Numerous entities in the country over the years have publicly reported attacks by cybercriminals, often being reported as one form or another of hacking. Quite often, entities are reluctant to either publicise that they have been hacked, or acknowledge that the hacking involved ransomware, as they believe this would undermine their reputational integrity.

From fear of losing customers’ confidence, to the consequences from regulators, to the threat of copycat attacks and sometimes, just sheer embarrassment, many entities, particularly in the public eye, would rather quietly deal or cope with ransomware or cybercriminal infiltration.

The Botswana Communications Regulatory Authority (BOCRA), however, recently blew the lid off the challenge, sharing statistics reported by the national Computer Security Incident Response Team (CSIRT), the national cyber emergency-response team.

The CSIRT was established several years ago under the Cybersecurity Act and operates with leadership from BOCRA.

“Botnet infections emerged as the most prevalent, which is a worrying situation as it shows that many of Botswana’s Internet Protocol (IP) addresses form part of botnets, a network of compromised devices remotely controlled by cybercriminals for malicious activities such as spam or data theft,” the regulator said.

Other top cybersecurity incidents and threats included leaked credentials which involve usernames and passwords that have been exposed or stolen through data breaches, making them accessible to unauthorised parties, as well compromised email accounts where email accounts or servers have been accessed or controlled by unauthorised users, often leading to data breaches, spam or phishing attacks.

Another growing trend, one which Mmegi was a victim of years ago, is the website defacement where the CSIRT has noted attacks where hackers alter the visual appearance or content of a website, usually to display unauthorised messages, propaganda, or offensive material. While the latter may appear almost harmless compared to ransomware, experts warn that the cybercriminals involve may use website defacement to test the vulnerability of a system and prepare for a more sinister attack.

The CSIRT shared its own observations on the trends in national cybersecurity.

“During the reporting period, the CSIRT observed a noticeable increase in cyber incidents, particularly during the festive season. “Threats targeted financial institutions and e-commerce users. “The distractions of the holiday season also led to lapses in awareness and heightened vulnerability.”

Malware infections, in the year to March 2025, were up 205 percent, the national cybersecurity team report.

For Garebatshabe, besides attacks against institutions, the greatest indicator of the country’s vulnerabilities are being seen at village level. The cybersecurity veteran has been championing the Village Digital Safety Botswana Initiative, a voluntary community outreach programme from village to village across Botswana to educate communities about digital safety.

“The first warning did not come from a government report or a cybersecurity company,” he said. “It came from a pensioner in a Botswana village. “She said I don't understand how they knew my pension had been paid. “Her question was followed by silence before others began sharing similar experiences. “Some had lost money through mobile money scams. Others had received convincing calls from people pretending to represent trusted organisations. “Many admitted they had become afraid to answer unfamiliar calls or even open messages on their phones, worried that a single mistake could cost them their savings.”

According to Garebatshabe, these conversations have become increasingly common across the country as the Village Digital Safety Botswana Initiative gathers steam.

The CSIRT is still bulking up its own capacity, benchmarking with international entities and rolling out institutional partnerships to protect the country’s cyberspace. At ground level, however, poor “digital hygiene” means ordinary Batswana are often victims of cyberspace.

In terms of digital hygiene, experts recommend the following for anyone with access to the Internet:

• Use strong, unique passwords • Turn on multi-factor authentication (MFA) • Keep software and operating systems updated • Be cautious about phishing emails, texts and suspicious links • Regularly back up important data • Install security software and keeping it updated • Avoid unsecured Wi-Fi when handling sensitive information • Remove old accounts and apps you no longer use