Insights & Data

AI Is Industrialising Africa’s Cybercrime Economy Faster Than Defences Can Respond Effectively

AI Is Industrialising Africa’s Cybercrime Economy Faster Than Defences Can Respond Effectively
Share

Artificial intelligence was linked to 55% of cybercrimes reported in INTERPOL’s 2026

African assessment, as estimated losses more than doubled from $192 million to $484 million.

The danger is not only smarter attacks. It is the speed at which cross-border criminal markets are growing more sophisticated than the tools, staffing and cooperation available to many African agencies.

Digital Growth Now Carries Systemic Exposure

Africa’s digital expansion has created extraordinary economic reach.

In 2025, the continent recorded more than 1.1 billion mobile subscriptions, over $1.1 trillion in digital transactions and roughly 570 million internet users.

The same networks are also providing criminals with a larger, faster and more interconnected market.

INTERPOL’s African Cyberthreat Assessment Report 2026 describes a threat economy moving from opportunistic fraud toward industrialised operations.

Generative artificial intelligence can translate messages, imitate trusted voices, automate victim targeting and help criminals produce convincing identities at low cost.

Scam centres organise that capacity into repeatable workflows.

The assessment draws on responses from 36 African countries and private-sector threat intelligence.

It is therefore a picture of reported incidents and observed telemetry, not a league table of national danger.

Countries with stronger monitoring may detect more.

However, the pattern is unmistakable: attack capacity is spreading faster than the continent’s collective ability to investigate and disrupt it.

Scams Now Move Across Every Channel

Online scams;

  • Including phishing, were the largest reported category at 17%.
  • Identity theft, financial fraud, sextortion, revenge pornography, cyberbullying, and harassment each accounted for 14%
  • Data breaches represented 11%
  • Business email compromise accounted for 10%.
  • Mobile-money fraud was reported by 97% of respondent countries.

Geography changes the form, not the urgency.

  • Kenya recorded 46,786 DDoS attacks in early 2025, alongside a 327% rise in SIM-swap fraud involving over 123,000 fraudulent SIM cards and $3.8 million in losses.
  • South Africa accounted for 92% of Africa's recorded ransomware detections and faced 213,523 DDoS attacks
  • Cabo Verde logged 16,997 ransomware detections and Nigeria 5,822.

Sextortion is becoming a significant digital harm, with roughly 600,000 detections continent-wide:

  • South Africa (30%)
  • Kenya (13%)
  • Côte d'Ivoire (11%)
  • Ethiopia (8%)
  • Angola (4%).

Victims include children and young adults whose social networks become instruments of intimidation.

Business email compromise reaches the real economy:

  • 70% of detected African BEC origin activity ties to South Africa
  • 29% to Nigeria, showing observed infrastructure rather than criminal nationality.

Defenders Face A Severe Capability Gap

The operational imbalance is stark.

  • 94% of responding countries reported insufficient digital forensics tools.
  • Only 17% had cybercrime units with more than 100 staff, while many operated with fewer than ten specialists.
  • Just 8% of analysts were assessed as having advanced AI capabilities
  • 92% of respondents identified lack of expertise as a barrier.

AI adoption by law enforcement remains limited:

  • 33% of agencies reported using it for threat detection and 31% for forensics or open-source intelligence.
  • Only 22% of digital-forensics units said they had working knowledge of AI-related threats. Criminals do not face the same procurement cycles, legal processes or staffing constraints.

The skills shortage extends beyond data scientists to first responders, prosecutors, victim-support workers, and financial investigators who need practical training and secure channels, not just sophisticated tools.

Coordination remains a major vulnerability:

  • 72% of countries reported slow inter-agency information exchange
  • 89% cited cross-border cooperation as their greatest barrier.

Fraudulent payments move across jurisdictions in minutes, while lawful evidence requests take weeks, a gap criminals exploit as a business model.

Scam centres illustrate this organising market, present in 72% of responding countries, concentrated in Southern and West Africa, blending recruitment, coercion, laundering and trafficking.

Stronger Institutions Can Reverse The Asymmetry

Africa is not starting from zero. 83% of responding countries have dedicated cybercrime laws, and 17 countries enacted or amended laws during 2025.

  • Burkina Faso combined a reporting platform with a national strategy.
  • Côte d’Ivoire advanced a digital-security bill.
  • Zambia adopted a Cyber Crime Act.
  • Mauritius set out a digital-transformation blueprint and cyber-agency reforms.
  • Senegal invested in capacity and child protection.

Operational successes show what coordinated action can achieve. In Senegal, authorities and partners froze an attempted $7.9 million business email-compromise transfer.

Such interventions work when banks, investigators, telecom operators, prosecutors and international partners share usable information quickly.

The broader opportunity is to treat cybersecurity as part of digital public infrastructure.

Secure identity, payment, cloud and connectivity systems protect development gains.

They also lower the cost of trust for businesses, governments and citizens.

Make Cooperation Faster Than Criminal Payments

Governments should establish 24-hour cybercrime contact points with clear authority to preserve data, trace payments and coordinate across borders.

Regional forensic services could give smaller states access to capabilities that are too expensive to build on their own.

Common evidence standards would make joint investigations faster and more likely to succeed.

Regulators require timely incident reporting from critical infrastructure, banks, telecoms and major platforms, coupled with safe channels for disclosure.

Banks and mobile-money providers need shared fraud indicators, rapid account freezing and transparent redress.

Schools and social services need referral pathways for sextortion victims.

AI should strengthen defenders without weakening rights. Procurement must include testing, auditability, data protection and human oversight.

The goal is not automated policing. It is faster triage, stronger evidence and earlier interruption of harm.

Path Forward – Africa Must Build Collective Cyber Resilience

No African country can contain a borderless cybercrime market on its own.

Shared intelligence, interoperable law and trusted cross-border teams are now essential infrastructure.

The decisive metric is not the number of strategies adopted.

It is whether institutions can stop a fraudulent transfer, protect a victim and preserve evidence before the criminal network disappears.

More Insights & Data

Start typing to search...