Artificial intelligence (AI) enabled 55% of cybercrimes reported by surveyed African countries in 2025, making attacks faster, more scalable and increasingly difficult to detect.
The finding appears in INTERPOL’s African Cyberthreat Assessment Report 2026, released on Monday, 3 August.
Drawing on responses from 36 African member countries, the report says cybercrime has evolved from isolated incidents into an industrialised, borderless ecosystem.
Reported cybercrime losses more than doubled from $192 million in 2024 to $484 million in 2025, driven mainly by AI-enabled scams, credential harvesting and automated social engineering campaigns.
The findings have implications for enterprises beyond higher attack volumes.
AI allows criminals to personalise phishing messages, impersonate executives and suppliers, automate reconnaissance and create synthetic identities capable of circumventing some verification systems.
This increases the exposure of banks, telecommunications companies and other organisations that rely on digital onboarding, remote payments and biometric authentication.
It also shifts cyber risk from a predominantly technical concern to an identity, financial control and business continuity issue.
Previous ITWeb reporting highlighted the same progression.
Business email compromise (BEC), phishing and ransomware were already among Africa’s leading cyberthreats before generative AI made fraudulent messages cheaper and easier to produce at scale.
Check Point Research also found that South African organisations faced an average of 1 850 cyberattacks a week in December 2025, with financial services, transport and logistics, and government among the main targets.
Separately, ESET data showed that phishing accounted for 32.5% of attacks targeting Africa and 45.7% of those targeting South Africa.
The INTERPOL assessment draws on information from member countries and data contributed by Fortinet, MasterCard, the Shadowserver Foundation, S2W and TrendAI.
Africa recorded more than 1.1 billion mobile subscribers in 2025 as its digital transformation accelerated. However, cybercrime legislation remains fragmented, while law enforcement agencies have limited readiness to investigate AI-enabled crime, according to the report.
East Africa emerged as a hub for mobile money fraud and ransomware targeting infrastructure. Online scams remained the most frequently reported type of cybercrime in 2025, with attackers using mobile money platforms, social media and AI to reach victims.
BEC and romance scams targeting corporate and individual victims were prevalent in Central and West Africa.
The threat also extended beyond the continent. Africa-based criminals used AI to create convincing e-mails in BEC campaigns targeting victims in Europe and North America, relying on infrastructure spread across several jurisdictions.
Southern Africa’s high connectivity has made it a target for global threat actors seeking widespread disruption, INTERPOL says. Scam centres were reported by 72% of surveyed countries, with the highest concentrations in Southern and West Africa.
Digital sextortion and online harassment, often facilitated by AI-generated deepfakes and synthetic media, also remained widespread. TrendAI recorded about 600 000 sextortion detections during the reporting period.
“Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack, from reconnaissance and phishing to extortion and evasion,” said Neal Jetton, director of INTERPOL’s Cybercrime Directorate.
“However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled,” he added.
Four INTERPOL-coordinated operations led to more than 1 500 arrests, the seizure of hundreds of devices and the recovery of more than $100 million.
However, the absence of real-time data sharing among banks, telecommunications companies and law enforcement agencies hampers attempts to combat financial fraud, the report says.
Criminals are exploiting this weakness by moving beyond stolen credentials and creating synthetic identities. By combining authentic personal data with fabricated details, these AI-generated personas can circumvent advanced biometric verification systems.
According to INTERPOL, criminals have used synthetic identities to open bank accounts, obtain mobile loans and register SIM cards under false names.
For enterprises, the findings point to the need for stronger payment verification, identity controls, employee awareness and information sharing.
Biometric authentication alone may be insufficient where criminals can combine stolen information, generated documents and synthetic media.
The report calls for standardised digital forensic capabilities, stronger cross-border co-operation, investment in AI literacy among law enforcement officers and formal public-private partnerships to improve prevention, detection and response.
Share


