Skip to content

Repository files navigation

Scope Type Focus Dark Web Project License

AFRINTEL - African Threat Intelligence

👉🏾 Version française


AFRINTEL is an open-source CTI project tracking cyberattacks targeting African organizations: ransomware, data leaks, access sales, and underground marketplace activity across 54 countries, monitored from dark web sources, leak sites, and OSINT.

Countries monitored Threat actors tracked Period covered Formats
54 100+ 2024-2026 Markdown, STIX 2.1, Visual CTI

AFRINTEL records publications observed on leak sites, underground forums and OSINT sources. Each incident retains the status documented in its victim card.


Featured reports

Cyber threats in Africa - June 2026

June 2026 recorded 40 cyber incident publications: 20 ransomware records and 20 data leaks or access sales. Morocco was the leading direct country label with 9 records, including 7 publications attributed to anisanas2. High-sensitivity cases include the biometric and KYC data exposure associated with Nigerian fintech Jeroid.co, plaintext credentials attributed to the Nigerian Army's webmail domain, and the claimed 10.2-million-record BRELA dataset in Tanzania.

📄 Full CTI report - June 2026 📋 Victim list - June 2026 📊 Visual intelligence - June 2026

First-half 2026 cyber threat report

From January to June 2026, AFRINTEL documented 239 Africa-related cyber incidents: 112 ransomware incidents, 126 data leaks or access sales, and 1 website defacement. The second quarter accounted for 157 incidents, compared with 82 in the first quarter. Ransomware remained stable at 56 incidents per quarter, while data leaks and access sales rose from 25 in the first quarter to 101 in the second quarter.

📊 Full H1 2026 report

🇫🇷 Rapport complet du S1 2026

📦 H1 2026 STIX 2.1 / OpenCTI bundle

🖼️ H1 2026 statistical visual for LinkedIn


Monthly CTI reports

Month FR EN
January 2026 Rapport Report
February 2026 Rapport Report
March 2026 Rapport Report
April 2026 Rapport Report
May 2026 Rapport Report
June 2026 Rapport Report
July 2026 in progress in progress

Statistics

Month FR EN
January 2026 Statistiques Statistics
February 2026 Statistiques Statistics
March 2026 Statistiques Statistics
April 2026 Statistiques Statistics
May 2026 Statistiques Statistics
June 2026 Statistiques Statistics
July 2026 in progress in progress

Month-over-month comparisons

Comparison FR EN
January vs February 2026 FR EN
February vs March 2026 FR EN
March vs April 2026 FR EN
April vs May 2026 FR EN
May vs June 2026 FR EN
H1 2026 report FR EN

Visual intelligence

Period Dashboard
January 2026 Visual intelligence
February 2026 Visual intelligence
March 2026 Visual intelligence
April 2026 Visual intelligence
May 2026 Visual intelligence
June 2026 Visual intelligence
H1 2026 Statistical LinkedIn visual

STIX / OpenCTI datasets

Dataset File
January 2026 STIX Bundle
February 2026 STIX Bundle
March 2026 STIX Bundle
April 2026 STIX Bundle
May 2026 STIX Bundle
June 2026 STIX Bundle
H1 2026 STIX Bundle

The monthly STIX 2.1 bundles include bilingual victim and incident descriptions, CTI reports, statistics, month-over-month comparisons, source references, AFRINTEL's organizational identity and the project author's identity. The H1 bundle consolidates the 239 January-June incidents and 36 bilingual analytical reports while preserving the monthly STIX IDs for OpenCTI correlation. Contextual MITRE ATT&CK mappings are documented in the report descriptions.


Project structure

AFRINTEL/
├── CyberAttackAfrica/   # Monthly victim lists and CTI reports (2024-2026)
├── statistics/          # Monthly statistics
├── comparison/          # Month-over-month comparisons
├── visual-intelligence/ # Ecosystem maps and diagrams
├── stix/                # STIX 2.1 / OpenCTI bundles
├── scripts/             # Validation and utility scripts
└── workflows/           # Automation workflows

✍🏿 Author

Adama ASSIONGBON - SOC & Cyber Threat Intelligence Consultant

🔗 LinkedIn | 📄 MIT License

About

AFRINTEL est une initiative de veille collaborative dédiée aux cybermenaces ciblant le continent africain. Le projet collecte, analyse et documente les incidents ransomware affectant les organisations africaines, en s'appuyant sur l'observation directe des sites de fuite sur le dark web.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors

Languages