Central African Republic — Cyber Threat Profile

The Central African Republic built its cyber legal framework only recently: in January 2024 it enacted Law No. 24.001 on the Protection of Personal Data, which covers any processing of personal data within the country or having effects in its territory, and a companion law on cybersecurity and the fight against cybercrime, pending adoption in January 2024 and promulgated by April that year, created the country's first Agence nationale de la cybersecurite (ANCY). The data protection law requires the Ministry of Digital Economy, Posts and Telecommunications to establish a supervisory authority within twelve months, with the ministry overseeing implementation until that body exists. Operational capability lags the legislation: a May 2023 Carnegie Endowment assessment found the country had no national Computer Incident Response Team, and the World Bank reported in January 2025 that only five of 22 countries in Western and Central Africa had at least one operational CSIRT as of 2024. The same World Bank fund financed a national cybersecurity maturity assessment in CAR to help identify gaps and investment opportunities. Exposure rests on a very thin digital base, with fibre-optic infrastructure reaching the country only at the end of 2023 and roughly 670,000 people, about 12 percent of the population, online at the end of 2025. The best-documented hostile activity against CAR is influence operations rather than intrusion: Meta's December 2020 takedown removed 61 Facebook accounts, 29 Pages, 7 Groups and 1 Instagram account in a Russia-origin network focused primarily on the Central African Republic and linked to the Internet Research Agency and to Yevgeniy Prigozhin, and the Africa Center for Strategic Studies counts eight Russian disinformation campaigns in CAR going back to at least 2018.

Read the full analysis on IntelFusions