
The same advertising systems built to help brands find the right customer are now becoming a quiet cybersecurity problem. Kaspersky is warning that ad-tech data, real-time bidding and brokered audience information can be abused by attackers that want to identify, track and compromise valuable targets.
The warning matters because advertising technology is not sitting at the edge of the internet anymore. It sits inside websites, mobile apps, smart devices and everyday digital services. Every time an ad request is made, a small packet of information about the user, device, location or browsing context may move through a chain of platforms. For marketers, that helps with targeting. For cybercriminals and espionage groups, it can become reconnaissance.
Kaspersky discussed the risk at its Cyber Security Weekend for the Middle East, Turkiye and Africa region, with coverage noting that the company blocked about 650,000 attempts to redirect users in South Africa to malicious content in the first half of 2026. The company has also warned separately that its systems stopped millions of online attacks across South Africa, Kenya and Nigeria during the same period, showing how broad the regional threat surface has become.
The concern is not that every ad network is malicious. The concern is that the ecosystem was designed for precision. A system that can find people by interest, device, geography or behaviour can also be misused to follow a journalist, executive, government worker, activist or engineer. In more serious cases, attackers can use advertising infrastructure to deliver malicious redirects or to help place spyware-style payloads closer to a chosen target.
This is where ad-tech becomes more than a privacy debate. For years, the conversation around tracking has focused on consent, cookies and whether companies know too much about users. The security angle is sharper. If the same data can help an attacker decide who is worth targeting, where they are likely to be, what device they use and what kind of website or app they frequent, the advertising supply chain becomes part of the attack surface.
One example often raised in this conversation is malicious redirect activity. A user may think they are visiting a normal page or opening a normal app, but a script or ad placement can push them toward malware or a fake page. That does not require the victim to go looking for danger. The danger is inserted into something ordinary.
This also connects with the wider AI-era security problem. Attackers are becoming better at personalisation, while defenders are trying to protect more devices, identities and cloud services than ever before. We recently wrote about Mirage Kitten malware and cyber-espionage risks in Africa and the Middle East, and about smart TV apps that quietly exposed users to proxy-network risks. The common thread is simple: ordinary digital services can become security channels when oversight is weak.
For African businesses, the practical lesson is that cybersecurity teams need to look beyond classic phishing, ransomware and firewall logs. Marketing pixels, third-party scripts, mobile SDKs, consent tools, analytics platforms and ad redirects also deserve attention. A company can spend heavily on endpoint security and still expose customers or employees through badly governed third-party code.
Regulators will also have to think about this more carefully. Privacy laws tend to ask whether data was collected lawfully. Security teams ask what that data can be used for after collection. Those are not the same question. If audience data can be bought, inferred, leaked or abused for targeting, then data protection and cybersecurity policy have to meet in the middle.
The advertising industry will not disappear, and it should not be treated as one giant threat. But the old idea that ad-tech risk is only about annoying tracking is outdated. The more precise digital advertising becomes, the more valuable it becomes to people who are not trying to sell anything at all.







