How misinformation is reshaping business security in Africa

How-misinformation-is-reshaping-business-security-in-Africa

ISJ hears exclusively from Fella J. Obala, Head of Intelligence and Research at Nairobi-based risk management company, Salama Fikira Group.

During the height of Kenya’s 2024 protests, many security managers discovered that their greatest challenge was not demonstrations themselves, but deciding which reports they could trust.

Road-closure alerts circulated before roads were blocked.

Videos from previous incidents resurfaced and were shared as live footage.

Employees forwarded warnings from family WhatsApp groups, while social media feeds produced a constant stream of alarming but often contradictory information.

In some cases, organisations postponed executive travel, instructed employees to work remotely and suspended non-essential operations based on reports that later proved inaccurate.

Several conferences and business meetings scheduled in Nairobi were either postponed or relocated during the June-August protest period, while tourism operators reported cancellations as international travellers monitored images and narratives circulating online.

The operational impact extended beyond areas directly affected by demonstrations.

A new reality has been exposed for the security community: uncertainty itself had become a threat.

For decades, corporate security professionals have focused on risks such as terrorism, organised crime, cyber-attacks and political instability.

Yet, across Africa, a less visible challenge is increasingly influencing operational decisions and disrupting businesses: the weaponisation of information.

Misinformation and influence operations are no longer political concerns alone.

They are operational risks that can disrupt staff safety, supply chains, corporate reputation and executive decision-making.

In today’s operating environment, false information can be detrimental to operations.

Information now belongs on the risk matrix as a distinct risk vector.

Rapid digital adoption and low trust in institutions have made Africa fertile ground for these threats – which now demand boardroom and security team attention.

The evolution of information threats

Although the terms are often used interchangeably, misinformation, disinformation and influence operations are distinct: misinformation is false or inaccurate information shared without malicious intent; disinformation is deliberately created and spread to deceive audiences; influence operations go further by using coordinated messaging to shape perceptions, behaviour or political outcomes.

Social media and advances in AI have accelerated all three.

Modern disinformation campaigns employ multiple vectors. AI-generated content, deepfakes, automated bot networks and coordinated online accounts can amplify misleading narratives at scale.

Different platforms also shape how information spreads.

Open platforms enable rapid amplification and trending narratives, while algorithm-driven platforms can quickly push emotionally charged content to large audiences.

Closed messaging applications present an additional challenge because information circulates within trusted networks where verification is difficult.

The actors behind campaigns vary in intent and methodology.

State-sponsored actors and external powers often conduct long-term influence operations designed to undermine trust, advance geopolitical interests or shape public opinion.

Domestic political actors may exploit disinformation to mobilise supporters or discredit opponents during periods of tension.

Opportunistic actors typically use false narratives for immediate gain.

Digital platforms have removed many traditional gatekeepers and enabled information to travel instantly.

Images, videos and claims can reach millions before they are verified.

In emotionally charged environments, speed often overwhelms accuracy.

For businesses operating in complex settings, this means security teams are no longer responding only to events, but to perceptions of events.

In some cases, perception can be more consequential than reality.

Why businesses should care

As noted earlier, information threats are no longer communication issues confined to public relations teams.

They have become enterprise risks.

False narratives can directly affect employee welfare: rumours about planned attacks, road closures or targeted violence can create anxiety among staff and lead to unnecessary evacuations, absenteeism or disruptions to normal operations.

Disinformation can also damage corporate reputations.

Companies perceived, rightly or wrongly, as supporting governments, opposition groups or controversial actors may become targets of broader political grievances.

Supply chains are equally vulnerable; transport disruptions triggered by protests, fear-driven decisions or inaccurate reporting can delay deliveries and undermine business continuity.

Executives travelling during periods of uncertainty also require intelligence support not only to understand what is happening, but to distinguish verified facts from speculation.

Kenya’s Gen Z protests

Kenya’s Gen Z protests in 2024 and 2025 offered a powerful example of how digital narratives can influence business security.

The protests emerged from genuine public frustration over economic pressure, governance concerns and unpopular taxation measures.

Social media played a central role in mobilising citizens, coordinating demonstrations and documenting alleged abuses.

Alongside legitimate activism, however, came misinformation, manipulated content and unverified claims.

Security teams across the country were forced to operate in an environment defined by uncertainty.

Videos from unrelated incidents recirculated as current events.

Old footage from previous protests reappeared online and gained traction.

Rumours about planned attacks, fatalities and demonstration locations spread through social media.

One major development was the emergence of narratives that identified certain establishments as aligned with the government or politically connected individuals.

Whether these perceptions were accurate became almost irrelevant.

Several businesses and commercial premises became symbolic representations of broader public grievances.

Organisations perceived to be associated with political elites, or viewed as beneficiaries of the existing system, attracted hostility from some protesters and opportunistic criminal elements.

Calls for boycotts circulated online.

In some cases, businesses became the subject of viral campaigns accusing them of supporting unpopular policies.

During periods of heightened tension, such narratives contributed to vandalism, looting and targeted attacks against establishments viewed as part of the political establishment.

Some organisations responded by adapting operational and comms strategies.

Several companies announced temporary branch closures to protect employees and customers, while others publicly expressed solidarity with the concerns raised by young Kenyans and adopted Gen Z-friendly language in their messaging.

By framing closures around staff welfare, rather than commercial disruption, these organisations sought to reduce reputational risks and avoid becoming symbolic targets.

For corporate security teams, traditional threat assessment proved insufficient.

The risk was not limited to where protests were taking place; it increasingly depended on how organisations were being perceived online.

Crisis comms teams faced equally difficult decisions: remaining silent risked creating uncertainty among stakeholders, while responding too quickly could inadvertently amplify false information.

The core challenge was therefore not simply unrest, but uncertainty.

Africa’s wider information battles

Kenya’s experience is not unique, reflecting a wider trend across the continent.

In Sudan, since the outbreak of conflict in 2023, humanitarian organisations have faced challenges caused by competing narratives and false reports online.

Fabricated claims regarding aid diversion and manipulated images have complicated efforts to verify conditions on the ground.

Moreover, during Ethiopia’s Tigray conflict, information became part of the conflict itself.

Reports from international media documented how competing narratives, internet restrictions and coordinated online campaigns sought to shape international opinion and domestic sentiment.

In Democratic Republic of Congo (DRC), misinformation has also periodically fuelled public anger towards international organisations and private companies.

In eastern DRC, false narratives accusing the United Nations Organisation Stabilisation Mission in the Democratic Republic of the Congo (MONUSCO) of supporting armed groups contributed to violent protests in 2022.

External powers, domestic political actors and organised criminal networks are all increasingly exploiting information spaces to advance their interests.

And, as a result, the distinction between physical security and information security is becoming increasingly blurred.

Lessons for security leaders

Security and risk management professionals can no longer treat information threats as someone else’s responsibility.

As misinformation and influence operations increasingly affect business continuity, organisations should build information resilience into their crisis-management structures.

A practical approach is to adopt a four-stage framework:

  • Anticipation – information risks should be monitored before they become operational risks. Organisations can use OSINT, media monitoring, sentiment analysis and horizon scanning to identify narratives that could affect staff, assets and operations
  • Verification – during periods of uncertainty, speed should not replace accuracy. Organisations should establish trusted networks that enable rapid verification of information through local contacts, field teams and reliable partners
  • Integration – information crises require a coordinated response. Security, comms, HR, legal and business continuity teams should operate as a unified crisis-management function. Regular tabletop exercises involving leadership can help clarify roles and decision-making responsibilities before a crisis occurs
  • Response – not every rumour requires a public response. Organisations should consider the following: does the narrative threaten staff safety, reputation or operations? Has the information gained sufficient visibility to influence stakeholder behaviour? If the answer to these questions is yes, a timely and transparent response may help contain the issue. If not, monitoring and internal preparedness may be more effective

Africa’s risk landscape is changing, and security leaders must adapt accordingly.

As narratives increasingly shape behaviour, the most dangerous threat may not always be what organisations know, but what they believe to be true.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox