Between 16 and 22 May 2026, South Africa experienced the largest distributed denial-of-service campaign in the country's recorded history. A group calling itself BlackMatter flooded every IP address owned by each major hosting provider simultaneously, sent ransom emails demanding cryptocurrency payment to stop the attacks, then kept flooding regardless of whether anyone paid. Network Platforms, 1-Grid, Xneelo, Domains.co.za, Liquid Intelligent Technologies, and Host Africa were all hit in sequence. At peak, one provider absorbed roughly one terabit per second of attack traffic for four consecutive hours.
Every major targeted provider refused to pay. The attacks eventually subsided without resolution. What the campaign left behind was a clear picture of where South Africa's internet infrastructure is structurally exposed, and a question that has not been fully answered: was this extortion, or was it reconnaissance for something larger?
Who BlackMatter is and what the ransom amount reveals
The name BlackMatter belongs to a DarkSide/BlackMatter ransomware-as-a-service operation that was active in 2020 and 2021 before shutting down under law enforcement pressure. Security analysts note that the name has been adopted by unrelated criminal groups since, and that the original operation was known for staging rebrands and using false flags to complicate attribution. The name was chosen to be recognised, not because of any operational connection.
The ransom demanded per target was set anomalously low relative to both the scale of the attack infrastructure and the precedent of the name being invoked. The economics of this campaign do not add up for a financially motivated operation where revenue is the goal.
Several security analysts concluded that the ransom amount was set precisely where it sits: low enough that almost any business might consider paying, which maximises intelligence about which targets respond to extortion, while the real return is the mapping of South Africa's DDoS resilience, response times, and infrastructure dependencies. The original BlackMatter operation ran demands multiple orders of magnitude higher per target. Something else is happening here.
How the May 2026 campaign unfolded
The attack campaign ran in waves across six days, escalating in volume and target scope with each successive wave.
What the attacks revealed about South Africa's internet infrastructure
The "carpet-bomb" technique used in this campaign was specifically designed to overwhelm fragmented defences. By flooding every IP address a provider owns simultaneously, rather than targeting a single server, the attacker forces the provider to either absorb the entire volume or take every client offline while mitigation infrastructure activates. South Africa's hosting and backbone providers do not have coordinated national-level DDoS scrubbing. Each handled its own mitigation individually.
Network Platforms routed traffic to scrubbing infrastructure in London. That path worked, but it revealed that South Africa's internet resilience depends on providers having pre-arranged international scrubbing relationships that are not universal across the industry. The Seacom collateral damage happened because there was no mechanism to coordinate traffic rerouting across operators in real time.
The government response gap was visible. Communications Minister Solly Malatsi convened a coordination response, but the existing structures, the Cybercrime Hub, cyber-police capacity, and the incident command framework, were not equal to the event. South Africa has cybercrime legislation. What does not yet exist is the operational response infrastructure that turns legislation into real-time incident handling.
What South African organisations should take away
The low ransom amount is the most instructive detail of this campaign. If revenue were the goal, the demand would be higher. Mapping which providers have scrubbing infrastructure, how long activation takes, and how the national internet handles a sustained multi-vector event is valuable intelligence for a future operation.
This campaign, charitably read, was an extremely low-margin extortion effort. Less charitably, it was a capabilities assessment of South Africa's internet infrastructure that our providers and government paid for in real disruption to hundreds of thousands of businesses. Neither reading is comfortable. Both point to the same preparation gap.
What South African organisations should do before the next campaign
-
Subscribe to DDoS scrubbing before you need it. The providers that maintained the most stability had scrubbing infrastructure pre-configured and active. Activating scrubbing mid-attack is slower and less effective than having it in place when the first packet arrives.
-
Ask your hosting provider about their DDoS response posture. Find out whether protection is opt-in or automatic, how long activation takes, and whether they have upstream scrubbing capacity beyond their own network.
-
Have an outage communication plan ready. When your hosted services go down, clients need information quickly. A pre-agreed communication process prevents the additional reputational cost of silence during an outage.
-
Know which email addresses receive extortion emails. The initial contact in this campaign was a ransom email to provider abuse and security inboxes. Know which addresses receive those emails, who reviews them, and what the escalation path is.
-
Do not pay a DDoS ransom. Payment confirms the model works, funds future operations, and rarely stops an active campaign immediately. None of the targeted providers paid, and the attacks subsided regardless.
Where Ubuntu Guard fits
Ubuntu Guard provides threat intelligence briefings and incident response planning for South African businesses. If your organisation relies on hosting infrastructure affected by the May 2026 campaign, or if you want to understand your current DDoS exposure and your provider's protection posture before the next event, we can work through those questions with you.
Reach us at [email protected]
Frequently asked questions
Should a business pay if it receives a DDoS extortion demand?
No. None of the major providers targeted in the May 2026 campaign paid the ransom, and the attacks subsided regardless. Paying confirms the model works, funds future operations, and does not guarantee the attacks stop. The correct posture is pre-arranged DDoS scrubbing and a clear internal escalation process agreed before any demand arrives.
How is a DDoS attack different from a data breach?
A DDoS attack floods a network with traffic until services become unreachable. No data is accessed or stolen. The damage is service disruption and the business cost of downtime. A data breach involves unauthorised access to and extraction of data. The May 2026 BlackMatter campaign was purely volumetric DDoS with no data exfiltration.
Was the BlackMatter DDoS campaign related to OpSouthAfrica?
No. The two ran concurrently but were completely separate operations by different actors with different objectives. BlackMatter was financial extortion targeting hosting infrastructure. Nullsec Nigeria was politically motivated hacktivism targeting government data. Treating them as the same campaign leads to misdirected security responses.
Sources
- TechCentral: BlackMatter DDoS reporting (techcentral.co.za, May 2026)
- ITWeb: DDoS campaign analysis (itweb.co.za, May 2026)
- MyBroadband: Network Platforms and Xneelo attack coverage (mybroadband.co.za, May 2026)
- BusinessTech: SA internet disruption reporting (businesstech.co.za, May 2026)
- Communications Minister Solly Malatsi: Public statement on government response (May 2026)