Cybercrime losses across Africa have more than doubled since 2024 β from USD 192 million to USD 484 million β and artificial intelligence is the engine behind much of that surge. That is the stark finding at the centre of INTERPOL's African Cyberthreat Assessment Report 2026, a 40-page document drawing on survey data from 36 African member countries.
According to the report, AI is now enabling 55 per cent of reported cybercrimes across the continent, making attacks faster, more scalable, and significantly harder to detect. The findings land against the backdrop of a continent that recorded more than 1.1 billion mobile subscribers in 2025 β a digital expansion that is proving to be a double-edged sword.
A Continent-Wide Threat, With Regional Flavours
The report paints a picture of a criminal ecosystem that has shifted from isolated incidents into what INTERPOL describes as an industrialised, borderless operation. Different regions are experiencing distinct threat profiles.
East Africa has emerged as a hub for mobile money fraud and ransomware attacks targeting critical infrastructure. Business email compromise (BEC) and romance scams are particularly prevalent in Central and West Africa, hitting both corporate victims and individuals. Southern Africa's high connectivity levels, meanwhile, make it a prime target for global threat actors seeking maximum disruption.
Online scams remained the single most reported cybercrime type in 2025, with attackers exploiting mobile money platforms, social media, and AI tools to reach victims at scale. 72 per cent of surveyed countries reported the presence of organised scam centres, with the heaviest concentrations found in Southern and West Africa.
Deepfakes, Synthetic Identities, and AI-Powered Fraud
The sophistication of attacks has grown sharply. Digital sextortion and online harassment β many of them facilitated by AI-generated deepfakes and synthetic media β have become widespread. TrendAI, one of several partners working with INTERPOL on this report, recorded roughly 600,000 sextortion detections alone.
BEC schemes have taken a troubling leap forward. Criminals are now using AI to craft highly convincing email correspondence, with Africa-based threat actors setting their sights on victims in Europe and North America, operating infrastructure spread across multiple jurisdictions to evade detection. This intersects with broader online safety concerns that have been escalating across the continent.
Perhaps the most alarming development in the report is the rise of synthetic identities. Criminals are no longer simply stealing existing credentials β they are building entirely new digital personas by combining real personal data with fabricated elements. These AI-generated identities have been used to open bank accounts, secure mobile loans, and register SIM cards under false names, bypassing even advanced biometric verification systems.
Law Enforcement Struggling to Keep Up
The report is direct about the structural gaps enabling this wave of crime. Cybercrime legislation across Africa remains fragmented, and AI readiness within law enforcement agencies is described as alarmingly low. The absence of real-time, inter-agency data sharing between banks, telecoms operators, and law enforcement creates what the report calls a dangerous blind spot in combating financial fraud.
Neal Jetton, Director of INTERPOL's Cybercrime unit, did not mince words on the severity of the situation.
"Cybercrime has emerged as one of the most significant criminal threats" facing the continent, Jetton said, signalling that the current trajectory demands urgent, coordinated action across member states.
The report's release adds fresh urgency to ongoing debates about AI governance and the role of artificial intelligence in both enabling and combating crime across Africa's fast-growing digital economies. With over a billion mobile subscribers and connectivity expanding into previously unserved communities, the window for getting cybersecurity frameworks right is narrowing fast.
INTERPOL has not yet published a full public release date for the complete report, but the findings are already circulating among member country agencies and cybersecurity stakeholders across the continent.
