Cybercrime threats to Africa in 2026 | #cybercrime | #infosec



There are now more than 1.1 billion mobile telephony subscribers across Africa. The continent’s digital economy is expanding rapidly, with US$1.1 trillion in digital transactions recorded in 2025. Against this backdrop, reported losses to cybercriminals totalled US$484 million.

A recent Interpol report, the African Cyberthreat Assessment Report 20261, found that artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa. Financial losses are mainly attributable to AI-facilitated scams, credential harvesting, and automated social-engineering campaigns.

The report covers January to December 2025 and draws on survey returns from law-enforcement agencies in 36 member countries, cross-referenced against data from security and payments companies. It states that 2025 marked the definitive transition from AI as a supporting tool to AI as the core operational driver of cybercrime in Africa.

The detail beneath those headline figures deserves a closer reading, particularly by companies headquartered outside Africa with operations on the continent. Read carefully, however, the report is also a record of how little is reliably known about individual incidents.

Mobile devices are central to victimisation

Mobile is the primary access point to the digital economy across Africa. Mobile devices are simultaneously the continent’s main gateway to the internet and the financial system, and the path by which cybercriminals reach their victims.

Mobile money platforms are the dominant financial infrastructure and, as a result, the dominant fraud target. Mobile money fraud was the most prevalent scam type reported, cited by 97 per cent of countries responding to the Interpol member-country survey.

Mobile channels carry scams end to end, from initial lure to payout. Romance-baiting scams recruit victims via Facebook and move them to WhatsApp for video calls, where they are coerced into sending money. Sextortion operations similarly establish fake relationships on Facebook, move victims to WhatsApp, capture explicit content, and then demand payment via mainstream mobile-money wallets such as M-Pesa or MTN Mobile Money.

There are currently approximately 600 million 2G/3G users who will migrate from legacy networks as they are removed to smartphone-based access, further increasing the dominance of mobile as a platform.

AI-related incidents

Deepfakes were the most visible manifestation of the move towards AI-enabled cybercrime. They are a prevalent problem. Much reporting focuses on cases that involve a major fraud, target a well-known brand, or are carried out in an especially audacious way. However, in practice most of the observed use is against individuals and involves low-value frauds.

This is likely the result of three converging factors: widespread access to AI tools, mobile-centric access that puts deepfakes easily in front of victims, and digital payment mechanisms that allow money to be transferred quickly.

Tackling deepfakes requires those being impersonated to act; the burden cannot be left to victims alone, who can only report issues when they occur on social media or web platforms. Further, legislation is often behind the times with regard to this type of online crime globally, making prosecution difficult.

High-profile incidents

The Uganda Electricity Transmission Company Limited (UETCL), the state-owned utility that runs the country’s high-voltage network, is described as having suffered a suspected ransomware incident in August 2025. Qilin, a criminal group operating a ransomware-as-a-service model, listed UETCL as a victim that month and claimed to hold contracts, identity documents, and financial statements.

Cybercrime legislation is fragmented across Africa

The African Union Convention on Cyber Security and Personal Data Protection, known as the Malabo Convention, was adopted in 2014. It came into force on 8 June 2023, once the minimum of 15 ratifications had been reached. At a continental level, there have been 20 ratifications among 55 member states.

Locally, however, the picture is better. UNCTAD, the UN trade and development body that tracks cyber-law adoption, reported in 2020 that 72 per cent of African states had cybercrime legislation, while a separate count published by the Media Institute of Southern Africa (MISA) put the figure at 46 states, or 85 per cent.

The issues now lie in international co-operation, given the cross-border nature of cybercrime. The Malabo Convention has been described as not going far enough to create an actionable framework to support this, and there are gaps in offences concerning online content that isn’t caught by traditional laws for the physical world.

AI readiness in law enforcement agencies remains alarmingly low

Ninety-four per cent of responding agencies said they lacked adequate digital forensic tools; sixty-six per cent said ransomware victims were generally unable to recover encrypted files; and eighty-nine per cent named cross-border co-operation as the most significant barrier to a successful investigation.

South Africa leads in connectivity and incident reports

South African public bodies have continued to be targeted in 2026. In March, Statistics South Africa, the national statistics agency, confirmed a breach by a group calling itself XP95, which claimed to have exfiltrated 154 gigabytes of data and demanded US$100,000. The agency said it would not pay and reported the breach to the Information Regulator.

The same group had already claimed to have taken 3.8 terabytes of data from the Gauteng provincial government that month, which was then offered for sale.

Sophos, the security vendor, reported in September 2026 that South African respondents to its survey put the average cost of recovering from ransomware at more than ZAR 17 million, excluding any ransom, and that only 40 per cent had recovered within a week, the lowest proportion among the countries surveyed.

What will drive change

Three areas stand out.

  • Without change at a continental level, there is a risk that the 900 million people currently offline in Africa will connect into a dangerous digital economy. Initiatives to support device affordability, digital skills, and relevant services must be underpinned by cybersecurity and fraud prevention.
  • International co-operation will need to increase, with a focus on the countries that lead in connectivity. There is an opportunity for countries across the continent to take the lead in making Africa safe online.
  • Law-enforcement capability will need to be strengthened, not just to deal with cybercrime, but to manage all crime where mobile devices or digital evidence feature.








Click Here For The Original Source.

——————————————————–

..........

.

.