Africa's digital -payment ecosystem could face a new class of cyber threat as artificial intelligence (AI) agents make payment-card attacks cheaper and faster at scale.
For this story, ITWeb Africa interviewed cybersecurity and AI specialists Stanislav Kazanov, Matt Goren and Alex Ferrer on how autonomous systems could reshape fraud, expose smaller merchants and challenge conventional detection tools.
The concern is illustrated by a cybercrime campaign investigated by Gambit Security, in which attackers used AI agents to target online retailers.
Gambit says 105 attack projects were launched between 10 and 15 September, with at least 27 companies compromised and more than 600 000 unexpired card records stolen from two victims. It estimates the campaign cost between $12 000 and $18 000.
The significance of the campaign lies in how much work AI can take over, says Stanislav Kazanov, head of governance, risk and compliance, cybersecurity and sustainability at Innowise.
One operator used 1 951 AI prompts across 260 sessions to carry out tasks that would previously have required a team of hackers, he says, allowing the attacker to automate and scale the operation.
AI-driven attacks could also expose gaps in conventional fraud detection, because activity distributed across multiple merchants may not appear suspicious when examined individually, says Matt Goren, founder of RunOctopus.
"Most screening looks at one merchant's traffic, and an attack spread thinly across 30 sites can look normal at each one," he says.
Financial institutions need network-level analysis capable of connecting seemingly unrelated transactions through common devices, payment instruments, infrastructure and behaviour, says Alex Ferrer, head of blockchain forensic investigations at Crypto Legal.
The experts identify smaller merchants as particularly exposed because many lack sophisticated security teams. They recommend measures including hosted payment pages, multi-factor authentication, updated software and transaction monitoring.
Kazanov also calls for closer collaboration between banks, payment companies and security specialists to identify stolen-card activity, while Ferrer says merchants, processors, banks, telecoms operators and authorities often hold different pieces of the same attack.
As attackers use AI to target several businesses at once, payment-security teams in Africa, where digital payments continue to expand, may need to look beyond individual transactions and identify suspicious patterns across the wider payment ecosystem.
Share


