By Jean-Pierre A.
A new cybersecurity report released by Interpol reveals that artificial intelligence is enabling more than 55 percent of reported cybercrimes in Africa, complicating efforts to detect and mitigate these threats.
Africa’s digital sector is growing fast, with more than 1.1 billion mobile subscribers recorded in 2025. However, online security is becoming a big challenge as cybercrime legislation is fragmented and AI readiness in law enforcement agencies remains alarmingly low, noted Interpol.
The report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialized, borderless ecosystem.
“Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion,” Neal Jetton, Director of INTERPOL’s Cybercrime unit said.
The most affected sectors include financial services, telecommunications, and government institutions, all of which serve as central nodes in the digital economy.
According to the report, East Africa emerged as a hub of mobile money fraud and infrastructure-targeted ransomware.
Business email compromise and romance scams targeting both corporate and individual victims were prolific in Central and West Africa, the report reveals.
According to the report authors, Southern Africa’s ultra-high connectivity makes it a magnet for global threat actors seeking maximum disruption.
The financial is significant
Since 2024, cybercrime-related losses have more than doubled, from USD 192 million to USD 484 million, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.
According to the report, in 2025, online scams continued to be the most reported type of cybercrime, with attackers leveraging mobile money platforms, social media and AI to reach their targets.
“Notably,72 per cent of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa,” the report states.
The new report shows a high volume of data breaches was observed, relating to users and organizations originating from South Sudan, South Africa, Nigeria, and Namibia, between January 2024 and September 2025.4 Ransomware incidents were similarly prevalent across South Africa, Nigeria, Namibia, Senegal, and Zambia, with attackers increasingly targeting healthcare institutions, utility providers, and public service portals to maximize disruption and extortion potential.
Online scams remain the most frequently reported cybercrime type across the region, often serving as the initial entry vector for identity theft and subsequent financial fraud. “These incidents form a cascading threat chain: compromised credentials lead to unauthorized access to financial accounts, digital wallets, and government services, enabling large-scale monetary extraction,” the report authors explain.
According to the report, the financial toll of cybercrime in Africa has intensified dramatically. Between 2024 and 2025, reported cybercrime-related losses more than doubled, rising from USD 192 million to USD 484 million. The number of identified victims increased from 35,000 to 87,000, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.
Central and West Africa experienced the highest rates of human-related incidents compared to other regions, with up to 75 per cent linked to employee behaviour.
The report says mobile credit application fraud became more prevalent in Côte d’Ivoire, while Cameroon and Chad have also been identified as areas of potential vulnerability. This is because the countries faced challenges related to unauthorized lending practices, including the use of non-standard debt recovery tactics such as public exposure threats and SIM lockouts.
East Africa emerged as a hub of mobile money fraud and infrastructure-targeted ransomware. Kenya recorded more than 46,786 DDoS attacks in the first half of 2025 targeting telecoms,14 and was included in SOCRadar’s top phishing detection in September 2025.
Uganda’s Electricity Transmission Company Limited (UETCL) experienced a suspected ransomware incident in August 2025, marking a case involving a national power grid.16 The incident highlighted potential areas for improvement in critical infrastructure resilience and incident response coordination.
The report reveals that the absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud.
In its recommendations, the report calls for standardized digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal-public private partnership to support effective prevention, detection and response.
Click Here For The Original Source.
