SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

MediumReportTLP: CLEARCBN-2026-035 · 09 Apr 2026

Africa's phishing targets banks, not shops — and infostealers now outpace banking trojans

Kaspersky found over a million online banking accounts at the world's largest banks with credentials circulating on the dark web. Regionally the picture diverges: 53.75% of financial phishing in Africa targets banks, against a global average of 26%.

At a glance

Affected

Mauritian banks and their customers, plus any organisation whose staff use personal or BYOD devices for work email.

Impact

Credentials harvested from an employee's home laptop reach corporate accounts without any corporate device ever being touched. 74% of compromised payment cards were still valid months later.

Action

Deploy EDR with credential-theft detections, replace browser password managers with an enterprise vault, force session-cookie invalidation on password reset, and subscribe to dark-web credential monitoring for your domains.

Client status

Dark-web credential monitoring for corporate domains and named executives is included in our managed detection service. Several Mauritian clients have had hits actioned this year.

Detail

Kaspersky's Financial Threat Report for 2025, published in April, documents a structural shift: financial crime is moving away from purpose-built banking trojans toward mass credential theft by infostealers. Infostealer detections on PCs rose 59% year on year. More than a million online banking accounts at the world's hundred largest banks had credentials circulating on dark-web forums. Mobile banker attacks grew by half.

The regional split is the finding that matters here

Globally, financial phishing has moved toward e-commerce: 48.5% of phishing pages target online shops, up 10.3 points on 2024, while bank-targeted phishing fell 16.5 points to 26.1%.

Africa did not follow. 53.75% of financial phishing pages in the region target banks — the leading category, and roughly double the global share. For comparison, the Middle East runs 85.8% e-commerce.

The practical reading for a Mauritian institution is that your brand is the lure. Attackers here are not going through merchant intermediaries; they are cloning retail banking login pages directly. Defensive domain registration, active monitoring for lookalike domains, and customer communication about how you will and will not contact them are therefore worth more in this market than the global averages would suggest.

The BYOD problem this creates

Infostealers harvest credentials from whatever browser profile they land in, which increasingly means a personal laptop that has a work mailbox signed in. The corporate device fleet can be immaculate and the credentials still leave. This is the argument for enterprise password vaulting over browser storage, and for forcing session-cookie invalidation on every password reset — a stolen session token bypasses MFA entirely, and a reset that leaves the old session live has fixed nothing.

An exposure window measured in months

74% of compromised payment cards in the data set were still valid as at March 2026. Whatever your reissue triggers are, they are probably slower than the resale market. For issuers, that argues for behavioural transaction monitoring and device binding rather than relying on card lifecycle alone.

The sample basis is Kaspersky Security Network telemetry from consenting users for calendar year 2025, supplemented by public and dark-web sourced data — vendor telemetry, with the usual caveats about product installation base shaping the regional picture.

If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.

Sources

Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.

  1. Kaspersky financial threat report 2025Olga Altukhova, Oleg Kupreev and Polina Tretyak·Securelist (Kaspersky)·8 April 2026
  2. Kaspersky report: Over a million banking accounts compromised as financial threats move to credential theftKaspersky·8 April 2026