The release of INTERPOL’s African Cyberthreat Assessment Report 2026 marks a critical turning point in regional cybersecurity. Cybercrime across Africa has transitioned from opportunistic, isolated attacks into an industrialized, borderless underground economy. Driven by the rapid expansion of Africa’s digital footprint—spanning 1.1 billion mobile subscriptions, 570 million internet users, and USD 1.1 trillion in annual digital transactions—the attack surface has broadened far faster than institutional defenses can adapt.
1. The Macro Picture: AI Acceleration and Financial Escalation
The defining insight of the 2026 assessment is the systemic integration of Artificial Intelligence (AI) across the entire cyberattack lifecycle. Key aggregate metrics from 36 surveyed African member countries include:
- 55% AI-Enabled Cybercrime: Over half of all reported cybercrimes in Africa now leverage AI tools to automate target reconnaissance, craft convincing social engineering campaigns, and evade detection.
- Financial Losses Doubling: Direct reported cybercrime losses soared from USD 192 million in 2024 to USD 484 million in 2025, with total estimated direct economic damage across the continent exceeding USD 5 billion.
- Defensive Spending Imbalance: While African entities spent an estimated USD 15.3 billion on cybersecurity in 2025, criminal velocity and attack scale continue to outpace security investments.
- Surge in Victimology: The number of officially recorded cybercrime victims grew from 35,000 in 2024 to 87,000 in 2025.
- Industrialized Scam Infrastructure: 72% of surveyed countries reported the physical presence of organized scam centers, heavily concentrated in West and Southern Africa.
2. Technical Egress: How Threat Actors Leverage AI
Cybercriminals are exploiting AI to eliminate traditional friction points in attack campaigns. The report highlights three critical technical evolutions:
Synthetic Identity Creation
Attackers have progressed beyond simple identity theft to constructing synthetic identities. By pairing stolen personal data—such as National Identification Numbers (NIN) and SIM registration records—with AI-generated biometric attributes (facial deepfakes and synthetic voice prints), criminal networks bypass traditional Know Your Customer (KYC) and biometric verification systems. These synthetic personas are used to open fraudulent bank accounts, secure unsecured micro-loans, and register untraceable SIM cards at scale.
Automated Reconnaissance and Botnets
Threat actors deploy machine learning-driven scanners capable of evaluating tens of thousands of IP addresses per second to identify unpatched software and cloud misconfigurations. Command-and-Control (C2) frameworks like the open-source Sliver Botnet are increasingly weaponized to maintain persistent access and drop multi-stage payloads, including 01flip ransomware. Cameroon recorded 40.5 million botnet detections in 2025—the second-highest volume on the continent—underscoring heavy device compromise.
Hyper-Personalized Social Engineering
Generative AI tools enable threat actors to execute high-volume, localized Business Email Compromise (BEC) and romance scams. By analyzing corporate communication patterns, executive tone, and sector jargon, attackers generate zero-error phishing lures in multiple languages (including French and English), rendering legacy signature-based email filters ineffective.
3. Regional Threat Breakdown
Cyberthreat dynamics across Africa exhibit distinct regional characteristics tied to connectivity levels, financial infrastructure, and regulatory enforcement.
| Region | Primary Attack Vectors & Operational Highlights |
| Southern Africa | • High-impact Ransomware & Heavy DDoS (South Africa: 92% of continent’s ransomware detections; 213,523 DDoS attacks) • Advanced BEC targeting global markets (US & Europe) |
| West Africa | • BEC Hub (Nigeria: 29% of BEC detections; 5,822 ransomware) • High Ransomware Spike (Cabo Verde: 16,997 detections) • Extortion via predatory French-language micro-loan apps |
| East Africa | • Mobile Money Fraud & SIM Swapping (Kenya: +327% surge) • Critical Infrastructure Ransomware (Uganda UETCL power grid) • High Infrastructure Intrusion Attempts & DDoS |
| Central Africa | • High Human Risk & Employee Phishing Exploitation (up to 75%) • High Botnet Density (Cameroon: 40.5M detections) • Prolific Romance Scams & Underreported Extortion |
Southern Africa: High Connectivity as a Vulnerability Vector
As the continent’s most digitally connected sub-region, Southern Africa serves as a primary target for global threat groups seeking maximum operational impact.
- South Africa accounted for 92% of all ransomware detections in Africa (TrendAI), suffering severe incidents such as the January 2025 attack on the South African Weather Service (SAWS) that disrupted aviation and maritime navigation feeds. South Africa also experienced 213,523 recorded DDoS attacks.
- Namibia faced multiple high-profile incidents, including a customer database breach at its national telecom provider by Hunters International and an Akira ransomware attack against Paratus Telecom.
West Africa: BEC & Industrialized Scam Operations
West Africa remains the central hub for Business Email Compromise and financial fraud networks.
- Nigeria represented 29% of regional BEC detections and recorded 5,822 ransomware detections, demonstrating its dual role as both an operational source and a major target. A breach of the Nigerian Bureau of Statistics (NBS) website disrupted national economic reporting.
- Cabo Verde registered a continent-leading spike in ransomware detections with 16,997 incidents.
- Côte d’Ivoire and Cameroon saw rapid growth in predatory mobile loan applications (e.g., “Wave Prêt”, “Crédit Max”) harvesting user data and extorting victims through automated harassment and public shaming threats.
East Africa: Mobile Money Ecosystem Exploitation
East Africa’s heavy reliance on digital financial services has driven targeted fraud against mobile wallets and utilities.
- Kenya saw SIM swap fraud investigations jump by 327%, with over 123,000 fraudulent SIMs issued to drain mobile money accounts, while enduring over 46,000 DDoS attacks against telecom infrastructure.
- Uganda experienced a major critical infrastructure breach in August 2025, when the Uganda Electricity Transmission Company Limited (UETCL) was hit by a Qilin ransomware attack targeting power grid monitoring systems.
Central Africa: Stealth Operations and Botnet Saturation
Characterized by lower incident reporting but high vulnerability, Central Africa suffers from persistent background compromise. Up to 75% of incidents were linked to human risk factors and employee behavior. Cameroon emerged as the second-largest botnet hub in Africa, hosting over 40.5 million botnet signals used for global credential harvesting.
4. Key Cybercriminal Threat Vectors
| Crime Type | Percentage of Reported Cybercrime (2025) |
| Online Scams (incl. Phishing) | 17% |
| Digital Sextortion / Harassment | 14% |
| Identity Theft & Financial Fraud | 14% |
| Cryptojacking / DDoS / Other | 12% |
| Data Breaches | 11% |
| Business Email Compromise (BEC) | 10% |
| Ransomware & Banking Trojans | 7% |
| Cyberattacks on Critical Infrastructure | 6% |
| Cybercrime-as-a-Service / Human Trafficking | 5% |
- Ransomware as Infrastructure Sabotage: Ransomware has evolved from simple data encryption to strategic sabotage of national supply chains and essential services. The August 2025 attack on the Nigerian Customs Service paralyzed port cargo clearance, causing an estimated USD 18 million in supply chain delays and storage losses.
- Digital Sextortion & Synthetic Media: Over 600,000 sextortion detections were recorded by TrendAI in 2025. Threat actors leverage deepfake generators to modify publicly scraped photos, using synthetic explicit content to extort victims. Mali registered the highest concentration of sextortion IP senders in West Africa.
- Investment & Crypto Fraud: Leveraging fake investment portals (such as CBEX, Optcoin, and AfriQuantumX) and deepfake endorsements of political leaders, criminal rings defrauded victims across Africa out of hundreds of millions of dollars.
5. Structural Bottlenecks & Operational Countermeasures
Systemic Challenges
The report highlights critical systemic gaps that impede effective cyber defense across the continent:
- Fragmented Legislation: While 17 member countries enacted or updated cybercrime laws in 2025, harmonization with international standards like the AU Malabo Convention remains uneven.
- Severe Underreporting: 89% of survey respondents noted that organizations fail to report cyber incidents due to fear of reputational damage, lack of legal mandates, or absence of forensic capabilities. Only a few nations (e.g., Nigeria, Kenya, South Africa, Mauritius, Ghana) enforce mandatory breach notification timelines.
- Inter-Agency Blind Spots: The lack of real-time data integration between telecommunications providers, commercial banks, and law enforcement agencies prevents early interception of fraudulent transactions.
Transnational Law Enforcement Victories
Despite structural limitations, joint operational enforcement yielded major disruptions in 2025 through the Africa Joint Operation against Cybercrime (AFJOC):
| Operation | Tangible Impact & Outcomes |
| Combined Operations (Serengeti 2.0, Contender 3.0, Sentinel, Red Card 2.0) | • 1,500+ arrests across Africa • Seizure of hundreds of digital devices • Over USD 100 million in illicit funds recovered |
| Operation Serengeti 2.0 | • Dismantled Zambia scam network: 15 arrests & recovered USD 300 million tied to 60,000 victims |
| Operation Sentinel | • Decrypted 30 Terabytes of ransomware data in Ghana • Intercepted USD 7.9 million Senegalese BEC scam |
6. Strategic Recommendations for Decision-Makers
To counter the industrialization of AI-enabled cybercrime, INTERPOL outlines four primary imperatives for African public and private sector leaders:
- Mandate Public-Private Information Sharing: Establish real-time threat intelligence sharing protocols connecting telecom operators, financial institutions, CERTs, and law enforcement to close identity verification blind spots.
- Elevate Law Enforcement AI Capabilities: Invest directly in digital forensics infrastructure and specialized AI literacy programs for law enforcement agencies to match modern criminal TTPs (Tactics, Techniques, and Procedures).
- Harmonize Legal & Evidence Frameworks: Standardize cross-border Mutual Legal Assistance Treaty (MLAT) channels and align national cybercrime laws with regional frameworks to streamline digital evidence collection.
- Enforce Strict KYC & Biometric Integrity: Require telecom and financial entities to implement multi-factor liveness detection to defend against AI-generated synthetic identity fraud.