The BlackMatter DDoS Attack on South Africa: A Full Account

By Ubuntu Guard | 26 May 2026 TLP:CLEAR

Between 16 and 22 May 2026, South Africa experienced the largest distributed denial-of-service campaign in the country's recorded history. A group calling itself BlackMatter flooded every IP address owned by each major hosting provider simultaneously, sent ransom emails demanding cryptocurrency payment to stop the attacks, then kept flooding regardless of whether anyone paid. Network Platforms, 1-Grid, Xneelo, Domains.co.za, Liquid Intelligent Technologies, and Host Africa were all hit in sequence. At peak, one provider absorbed roughly one terabit per second of attack traffic for four consecutive hours.

Every major targeted provider refused to pay. The attacks eventually subsided without resolution. What the campaign left behind was a clear picture of where South Africa's internet infrastructure is structurally exposed, and a question that has not been fully answered: was this extortion, or was it reconnaissance for something larger?

1 Tbps
Peak attack volume (Host Africa)
676 Gbps
Peak on Network Platforms / Xneelo
6 days
Campaign duration
6
Major providers targeted

Who BlackMatter is and what the ransom amount reveals

The name BlackMatter belongs to a DarkSide/BlackMatter ransomware-as-a-service operation that was active in 2020 and 2021 before shutting down under law enforcement pressure. Security analysts note that the name has been adopted by unrelated criminal groups since, and that the original operation was known for staging rebrands and using false flags to complicate attribution. The name was chosen to be recognised, not because of any operational connection.

The ransom demanded per target was set anomalously low relative to both the scale of the attack infrastructure and the precedent of the name being invoked. The economics of this campaign do not add up for a financially motivated operation where revenue is the goal.

Several security analysts concluded that the ransom amount was set precisely where it sits: low enough that almost any business might consider paying, which maximises intelligence about which targets respond to extortion, while the real return is the mapping of South Africa's DDoS resilience, response times, and infrastructure dependencies. The original BlackMatter operation ran demands multiple orders of magnitude higher per target. Something else is happening here.

How the May 2026 campaign unfolded

The attack campaign ran in waves across six days, escalating in volume and target scope with each successive wave.

Friday 16 May
Initial disruption across multiple providers from heavy UDP flood activity.
Monday 19 May
Network Platforms hit at approximately 13:25. Inbound traffic exceeds 300 Gbps. Ransom emails received. NP enables scrubbing for all clients and refuses to pay. 1-Grid also hit; outages mitigated by evening.
Tuesday 20 May
Xneelo (formerly Hetzner SA) suffers widespread disruption. Peak traffic on one host: approximately 676 Gbps. Control panels, hosted services, and email become intermittently inaccessible.
Wednesday 21 May
Domains.co.za and Liquid Intelligent Technologies targeted. Host Africa hit with approximately 1 Tbps sustained for approximately four hours.
Wednesday 20–21 May
Seacom (submarine cable operator) suffers a temporary outage from spillover traffic. Seacom was not directly targeted; congestion caused by simultaneous attacks on other providers.
Thursday–Friday 22–23 May
Attacks subside. No targeted provider had paid the ransom. Providers warn attacks could recur.

What the attacks revealed about South Africa's internet infrastructure

The "carpet-bomb" technique used in this campaign was specifically designed to overwhelm fragmented defences. By flooding every IP address a provider owns simultaneously, rather than targeting a single server, the attacker forces the provider to either absorb the entire volume or take every client offline while mitigation infrastructure activates. South Africa's hosting and backbone providers do not have coordinated national-level DDoS scrubbing. Each handled its own mitigation individually.

Network Platforms routed traffic to scrubbing infrastructure in London. That path worked, but it revealed that South Africa's internet resilience depends on providers having pre-arranged international scrubbing relationships that are not universal across the industry. The Seacom collateral damage happened because there was no mechanism to coordinate traffic rerouting across operators in real time.

The government response gap was visible. Communications Minister Solly Malatsi convened a coordination response, but the existing structures, the Cybercrime Hub, cyber-police capacity, and the incident command framework, were not equal to the event. South Africa has cybercrime legislation. What does not yet exist is the operational response infrastructure that turns legislation into real-time incident handling.

What South African organisations should take away

The low ransom amount is the most instructive detail of this campaign. If revenue were the goal, the demand would be higher. Mapping which providers have scrubbing infrastructure, how long activation takes, and how the national internet handles a sustained multi-vector event is valuable intelligence for a future operation.

This campaign, charitably read, was an extremely low-margin extortion effort. Less charitably, it was a capabilities assessment of South Africa's internet infrastructure that our providers and government paid for in real disruption to hundreds of thousands of businesses. Neither reading is comfortable. Both point to the same preparation gap.

What South African organisations should do before the next campaign

Where Ubuntu Guard fits

Ubuntu Guard provides threat intelligence briefings and incident response planning for South African businesses. If your organisation relies on hosting infrastructure affected by the May 2026 campaign, or if you want to understand your current DDoS exposure and your provider's protection posture before the next event, we can work through those questions with you.

Reach us at [email protected]

Frequently asked questions

Should a business pay if it receives a DDoS extortion demand?

No. None of the major providers targeted in the May 2026 campaign paid the ransom, and the attacks subsided regardless. Paying confirms the model works, funds future operations, and does not guarantee the attacks stop. The correct posture is pre-arranged DDoS scrubbing and a clear internal escalation process agreed before any demand arrives.

How is a DDoS attack different from a data breach?

A DDoS attack floods a network with traffic until services become unreachable. No data is accessed or stolen. The damage is service disruption and the business cost of downtime. A data breach involves unauthorised access to and extraction of data. The May 2026 BlackMatter campaign was purely volumetric DDoS with no data exfiltration.

Was the BlackMatter DDoS campaign related to OpSouthAfrica?

No. The two ran concurrently but were completely separate operations by different actors with different objectives. BlackMatter was financial extortion targeting hosting infrastructure. Nullsec Nigeria was politically motivated hacktivism targeting government data. Treating them as the same campaign leads to misdirected security responses.

Sources

  • TechCentral: BlackMatter DDoS reporting (techcentral.co.za, May 2026)
  • ITWeb: DDoS campaign analysis (itweb.co.za, May 2026)
  • MyBroadband: Network Platforms and Xneelo attack coverage (mybroadband.co.za, May 2026)
  • BusinessTech: SA internet disruption reporting (businesstech.co.za, May 2026)
  • Communications Minister Solly Malatsi: Public statement on government response (May 2026)

Is your business ready for the next DDoS campaign?

Ubuntu Guard's threat intelligence briefings and incident response planning help South African organisations understand their exposure and prepare their response before an attack arrives.

Book a Threat Intelligence Briefing

Questions? Reach us at [email protected]