Legal News

Colonel Aly Mime Sénégal: Zéro Rançon Pour Cyberattaques Administrations Publiques

Senegal·Briefly Analysis⏱️ 4 min read

Summary

  • Colonel Aly Mime, Director General of Encryption and Information Systems Security, confirmed Senegal has never paid ransom for cyberattacks on public administrations, including the DAF, Treasury, and DGID.
  • He stated cybercriminals often exaggerate data claims, while technical analyses confirmed malicious origins and unauthorized data dissemination in past incidents.
  • Interpol's 2026 report identifies Senegal among the most targeted African countries for cybercrime, with ransomware prevalent in the region.
  • Senegal's strategy focuses on resilience and rapid system restoration, with a thwarted $7.9 million diversion attempt against an oil company highlighting ongoing threats.
  • On August 20, 2026, the National Assembly approved a new law on critical information infrastructure protection and digital security, explained by Minister Samba Diouf as crucial for securing national digital platforms.

Senegal's Firm Stance Against Cyber Ransom

This steadfast approach applies even to significant incidents, including those that have impacted critical entities like the Directorate of Financial Affairs (DAF), the Treasury, and the Directorate General of Taxes and Domains (DGID).

Senegal maintains a resolute policy against paying ransoms in the wake of cyberattacks targeting its public administrations. Colonel Aly Mime, Director General of Encryption and Information Systems Security, recently affirmed that the state has never capitulated to such demands. This steadfast approach applies even to significant incidents, including those that have impacted critical entities like the Directorate of Financial Affairs (DAF), the Treasury, and the Directorate General of Taxes and Domains (DGID).

Colonel Aly Mime further noted that cybercriminals frequently inflate the volume of data they claim to have exfiltrated, characterizing many of their assertions as mere "bluffs." Despite this, the attacks are not without tangible operational consequences. Following one such incident, the Directorate General of Public Accounting and Treasury was compelled to announce a phased restoration of its payment and collection services. Technical investigations subsequently confirmed the malicious nature of the breach and the unauthorized dissemination of information, with dedicated teams working diligently to secure and restore the compromised systems. This policy of non-payment underscores Senegal's commitment to resilience rather than negotiation in the face of digital extortion, a strategy that also saw the successful thwarting of an attempt to divert $7.9 million from an oil company operating within the country.

Escalating Cyber Threats and National Resilience

The challenges faced by Senegal extend beyond isolated incidents, reflecting a broader regional and global trend of escalating cyber threats. According to a 2026 report by Interpol, Senegal is identified among the African nations most frequently targeted by cybercriminals. The report highlights a significant prevalence of ransomware attacks across the continent, specifically citing numerous occurrences in countries such as South Africa, Nigeria, Namibia, Zambia, and Senegal itself.

In response to this persistent and evolving threat landscape, the Senegalese government prioritizes building resilience and ensuring the swift restoration of its information technology systems. Colonel Aly Mime acknowledges the inherent difficulties in definitively attributing cyberattacks, largely due to the sophisticated use of tools like the Darkweb and Virtual Private Networks (VPNs) by the perpetrators. Consequently, bolstering national cybersecurity has become a paramount concern, driving legislative action to safeguard critical digital infrastructure.

New Legislation Bolsters Digital Security

In a significant move to fortify its digital defenses, Senegal's National Assembly approved a comprehensive law on the protection of critical information infrastructure and digital security on August 20, 2026. The legislation received overwhelming support, passing with a majority vote of 127 deputies. This landmark act underscores the nation's proactive approach to enhancing its cybersecurity posture and protecting essential services from malicious digital intrusions.

Minister Samba Diouf elaborated on the objectives of this new legal framework, explaining that its primary purpose is to secure national information systems and digital platforms. This legislative development is particularly relevant for lawyers and compliance officers in Senegal, as it establishes a clear regulatory foundation for cybersecurity, necessitating a review of existing protocols and compliance measures for entities operating within or interacting with the country's critical sectors. The law reinforces the government's commitment to a robust national cybersecurity strategy, complementing its explicit policy against paying ransoms for cyberattacks and impacting incident response strategies across the board.

Practical Implications

Lawyers and compliance officers in Senegal should note the government's explicit policy against paying ransoms for cyberattacks, which impacts incident response strategies. Furthermore, the newly approved law on critical information infrastructure and digital security necessitates a review of existing cybersecurity frameworks and compliance measures for entities operating within or interacting with Senegal's critical sectors.

Source

Source: Original reporting via pressafrik

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Finish Reading the Full Story and the Expert Analysis.

Get the latest legal & regulatory intelligence in Senegal

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.