The disparity is allowing cybercriminals to automate scams, impersonate corporate executives, create synthetic identities and attack financial institutions faster than many African security agencies can respond, according to INTERPOL’s African Cyberthreat Assessment Report 2026.
The report draws on information from 36 African countries, alongside cyberthreat data provided by Mastercard, Fortinet, TrendAI, the Shadowserver Foundation and other private-sector partners.
INTERPOL surveyed 49 African member countries and received responses from 36, representing a response rate of 73%. The assessment covers cybercrime activity observed between January and December 2025.
It found that AI was used occasionally in 47% of cybercrime cases and frequently in another 8%, meaning the technology played some role in 55% of the cases observed.
In contrast, only 22% of digital forensic units had working knowledge of AI-driven threats, while just 8% of intelligence analysts possessed advanced expertise.
About 92% of agencies identified insufficient technical expertise as the main barrier preventing them from adopting AI tools.
INTERPOL said cybercrime had developed into “an industrialized, borderless ecosystem.”
Criminals move at machine speed
Cybercriminals are using AI throughout the attack process, from identifying potential victims and creating personalised phishing messages to generating malicious software and moving stolen money.
The report found that criminals used AI to write emails that imitated the tone, vocabulary and signature styles of corporate executives.
The messages were then sent to finance and procurement employees with instructions to change payment details or transfer money into accounts controlled by criminal networks.
AI-generated voice and video clips were also used to impersonate government officials, business leaders and victims’ relatives.
Deepfake incidents increased sevenfold across Africa between the second and fourth quarters of 2024, according to data cited in the assessment.
In Uganda, a deepfake video impersonating a prominent public figure was used to promote a fraudulent investment platform, resulting in more than $2 million in losses before authorities intervened.
Criminals also created synthetic identities capable of bypassing Know Your Customer checks and produced phishing messages tailored to information collected about individual victims.
INTERPOL warned that AI-generated malware is becoming more autonomous. The report highlighted PromptLock, an emerging ransomware strain capable of using generative AI to write and modify malicious code.
“Criminals are now operating at machine speed,” the report said.
African law-enforcement agencies, however, remain constrained by manual investigative processes, slow legal procedures and limited access to forensic technology.
Only 33% of surveyed agencies said they used AI for threat detection, while 31% applied it to digital forensics and open-source intelligence analysis.
Cybercrime inflicts at least $5 billion in damage
The financial cost of cybercrime across Africa is growing alongside the continent’s digital economy.
Africa recorded more than 1.1 billion mobile subscriptions and processed over $1.1 trillion in digital transactions during 2025. Approximately 570 million people now use the internet for banking, government services, healthcare, education and other activities.
Reported cybercrime losses more than doubled from $192 million in 2024 to $484 million in 2025.
The number of identified victims also increased from 35,000 to 87,000, driven by AI-enabled scams, stolen login credentials and automated social-engineering campaigns.
INTERPOL said broader estimates indicated that cybercrime caused at least $5 billion in direct economic damage across Africa in 2025, compared with the continent’s estimated cybersecurity expenditure of $15.3 billion.
The actual loss could be higher because many attacks are never disclosed.
About 89% of surveyed agencies identified underreporting as a serious problem. Businesses and public institutions frequently withhold information because of reputational concerns, uncertainty over disclosure obligations or an inability to investigate attacks properly.
Only Ghana, Nigeria, Kenya, South Africa and Mauritius were identified in the report as requiring cyber incidents to be disclosed within 72 hours. Ghana requires reporting within 24 hours, while the other four countries apply a 72-hour deadline.
South Africa and Nigeria dominate corporate email fraud detections
Business email compromise has become one of the most profitable parts of Africa’s cybercrime economy.
TrendAI data cited by INTERPOL showed that 70% of BEC detections originating in Africa came from South Africa, while Nigeria accounted for 29%.
Together, both countries represented 99% of the BEC detections captured in the dataset. This does not mean they accounted for 99% of every corporate email fraud case committed across Africa.
South Africa-based groups mainly targeted companies in the United States, using compromised email accounts and networks of money mules to divert corporate payments.
Nigerian groups were linked to international money-laundering operations that moved stolen funds through cryptocurrency exchanges, shell companies and mobile-payment platforms.
During INTERPOL’s Operation Sentinel, authorities disrupted an attempt by a Senegal-based network to divert $7.9 million from a petroleum company.
The payment was frozen before the money could be withdrawn. However, the investigation found that the fraud involved perpetrators in Africa, victims overseas and digital infrastructure spread across several jurisdictions.

Mobile money creates another attack surface
Mobile money fraud was reported by 97% of countries that responded to INTERPOL’s survey, making it the most widespread scam category identified.
Kenya detected more than 123,000 fraudulent SIM cards in 2025 as SIM-swap investigations increased by 327%. Criminals reportedly drained an estimated $3.8 million from mobile wallets.
Ghanaian users lost about $1.3 million to mobile money fraud during the first quarter of 2025.
Tanzania, however, recorded a 19% reduction in attempted mobile fraud after strengthening SIM-registration enforcement, demonstrating how improved identity verification can reduce attacks.
The report said weak and inconsistent KYC systems allow criminals to hijack phone numbers, gain access to mobile wallets and intercept security codes used for banking transactions.
Scam centres were also reported in 72% of surveyed African countries, with the highest concentration in Southern and West Africa.
INTERPOL described these centres as organised businesses with structures for recruiting participants, acquiring technology, laundering money and avoiding law enforcement. Some are connected to human trafficking, with people held against their will and forced to participate in online scams.
African police lack forensic tools and personnel
The expansion of AI-enabled crime comes as African cybercrime units face severe shortages of equipment and trained personnel.
About 94% of surveyed agencies said they lacked adequate digital forensic tools, while 78% reported insufficient budgets, specialist personnel and operational equipment.
Only 17% of countries had cybercrime units employing more than 100 people. Many units operated with fewer than 10 officers.
Slow cooperation between institutions is another obstacle. About 72% of respondents reported delays in exchanging data between agencies, while 89% described cross-border cooperation as the biggest barrier to successful cybercrime investigations.
Legal differences also allow criminals to move between jurisdictions.
Although 83% of responding countries had dedicated cybercrime legislation, the remaining 17% relied on older general laws or were still drafting legislation.
Some national laws do not explicitly criminalise deepfake fraud, cryptojacking, cyberstalking or online human trafficking.
The result is a growing imbalance in which criminal networks can deploy AI across borders almost instantly, while investigators must navigate different legal systems, court orders and lengthy evidence-sharing procedures.
INTERPOL called for greater investment in AI training, digital forensic laboratories, cross-border information sharing and real-time collaboration between law enforcement, banks, telecom companies and technology platforms.
Click Here For The Original Source.
