

CYBERCRIME AND THE NEW FACE OF ORGANISED CRIME IN KWAZULU-NATAL
By Gittins Attorneys · 8 min read · 03 July 2026
We explored the evolution of the physical extortion economy in KwaZulu-Natal, examining how organised criminal groups have expanded their influence from construction sites into sectors such as retail, hospitality and transport. As businesses have responded by strengthening physical security, improving access control and pursuing legal remedies, criminal enterprises have adapted their methods. Increasingly, they are shifting their focus to a threat that is less visible but equally disruptive; cybercrime.
The digital economy has transformed the way businesses operate, creating greater efficiency, connectivity and commercial opportunity. However, these same technological advancements have also created new opportunities for organised crime. Cybercrime is no longer confined to large multinational corporations or financial institutions. Businesses of every size now rely on interconnected digital systems to manage payments, supply chains, customer information and day-to-day operations. A successful cyberattack can therefore result in significant financial losses, operational disruption, reputational harm and extensive legal obligations.
THE GROWING DIGITAL THREAT
KwaZulu-Natal occupies a unique position within South Africa's economy. As home to the Port of Durban, extensive manufacturing hubs and one of the country's busiest freight corridors, businesses within the province process vast volumes of commercial transactions and sensitive information every day. These characteristics make the province an attractive target for sophisticated cybercriminals who increasingly view businesses as lucrative opportunities for extortion.
One of the most prevalent threats is Business Email Compromise. Rather than exploiting technical vulnerabilities, these attacks often exploit human trust. Criminals impersonate suppliers, service providers or senior executives and insert fraudulent banking details into legitimate payment instructions or invoice chains. These communications frequently occur within genuine email conversations, the deception is often only discovered after payment has been made. For businesses operating within logistics and shipping, where payment delays can interrupt supply chains and contractual obligations, the consequences can be substantial.
Ransomware attacks have also evolved considerably. While early attacks focused primarily on encrypting office computers, modern ransomware is capable of disabling production facilities, inventory management systems, logistics software and other operational technology that businesses rely upon daily. Criminals then demand payment in exchange for restoring access to critical systems. For businesses operating under tight commercial deadlines, prolonged downtime can prove more damaging than the ransom demand itself.
Perhaps the most concerning development is the rise of double extortion. Rather than merely encrypting data, cybercriminals first steal confidential commercial information, intellectual property and personal information relating to employees or customers. Victims are then threatened with the publication or sale of the stolen information if payment is not made. This approach significantly increases pressure on businesses, as they must respond not only to operational disruption but also to the potential legal and reputational consequences of a data breach.
LOOKING AHEAD
As demonstrated, organised crime in KwaZulu-Natal continues to evolve alongside the commercial environment. Whether through construction-site intimidation, protection rackets or sophisticated cyberattacks, criminal organisations pursue the same objective: exploiting business vulnerability for financial gain. The methods may have changed, but the underlying threat remains constant. Businesses must therefore adopt an equally adaptive approach.
Cybersecurity should form part of a broader governance and risk management strategy that combines robust technical safeguards with employee awareness, effective internal controls and proactive legal oversight. Organisations that prepare for cyber incidents before they occur are better positioned to minimise operational disruption, comply with their statutory obligations and maintain the confidence of customers, regulators and commercial partners.
Thank you for examining the evolving risks facing businesses in KwaZulu-Natal. We trust these insights have provided a practical understanding of the legal and commercial challenges presented by organised crime in both the physical and digital environments. Should your organisation require advice on cybersecurity governance or POPIA compliance, our team would be pleased to assist.







