Cheap AI attacks threaten Africa's smaller merchants

Stanislav Kazanov, head of governance, risk and compliance, cybersecurity and sustainability at Innowise; Matt Goren, founder of RunOctopus; and Alex Ferrer, head of blockchain forensic investigations at Crypto Legal.
Stanislav Kazanov, head of governance, risk and compliance, cybersecurity and sustainability at Innowise; Matt Goren, founder of RunOctopus; and Alex Ferrer, head of blockchain forensic investigations at Crypto Legal.

Africa's digital -payment ecosystem could face a new class of cyber threat as artificial intelligence (AI) agents make payment-card attacks cheaper and faster at scale.

For this story, ITWeb Africa interviewed cybersecurity and AI specialists Stanislav Kazanov, Matt Goren and Alex Ferrer on how autonomous systems could reshape fraud, expose smaller merchants and challenge conventional detection tools.

The concern is illustrated by a cybercrime campaign investigated by Gambit Security, in which attackers used AI agents to target online retailers.

Gambit says 105 attack projects were launched between 10 and 15 September, with at least 27 companies compromised and more than 600 000 unexpired card records stolen from two victims. It estimates the campaign cost between $12 000 and $18 000.

The significance of the campaign lies in how much work AI can take over, says Stanislav Kazanov, head of governance, risk and compliance, cybersecurity and sustainability at Innowise.

One operator used 1 951 AI prompts across 260 sessions to carry out tasks that would previously have required a team of hackers, he says, allowing the attacker to automate and scale the operation.

AI-driven attacks could also expose gaps in conventional fraud detection, because activity distributed across multiple merchants may not appear suspicious when examined individually, says Matt Goren, founder of RunOctopus.

"Most screening looks at one merchant's traffic, and an attack spread thinly across 30 sites can look normal at each one," he says.

Financial institutions need network-level analysis capable of connecting seemingly unrelated transactions through common devices, payment instruments, infrastructure and behaviour, says Alex Ferrer, head of blockchain forensic investigations at Crypto Legal.

The experts identify smaller merchants as particularly exposed because many lack sophisticated security teams. They recommend measures including hosted payment pages, multi-factor authentication, updated software and transaction monitoring.

Kazanov also calls for closer collaboration between banks, payment companies and security specialists to identify stolen-card activity, while Ferrer says merchants, processors, banks, telecoms operators and authorities often hold different pieces of the same attack.

As attackers use AI to target several businesses at once, payment-security teams in Africa, where digital payments continue to expand, may need to look beyond individual transactions and identify suspicious patterns across the wider payment ecosystem.

Share

Read more
ITWeb proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to enquiries@ombudsman.org.za. Contact the Press Council on 011 484 3612.
Copyright @ 1996 - 2026 ITWeb Limited. All rights reserved.