AI now powers over half of Africa's cybercrime, Interpol finds

By Adaeze Nwosu
AI-driven cybercrime now accounts for 55% of all reported digital crime in  Africa, according to Interpol's African Cyberthreat Assessment Report 2026:  https://t.co/b0cp8dv5fm

Criminals are adopting AI faster than law enforcement, using deepfakes and synthetic identities to defraud banks, telcos, and governments.

Share

Everyone knows cybercrime is rising in Africa. The assumption, repeated in conference panels and boardrooms, is that the region's attackers are largely unsophisticated — opportunistic scammers running romance fraud and lottery cons from internet cafés. The data no longer supports that assumption. INTERPOL's African Cyberthreat Assessment Report 2026, released on 3 August 2026, shows that artificial intelligence was involved in 55% of reported cybercrime cases across the continent in 2025. The criminals have industrialised. The institutions chasing them have not.

This is not a marginal shift. It is a structural reversal of the traditional asymmetry in cybersecurity — the one where defenders held the advantage of scale, training, and tooling. INTERPOL's own framing is blunt: "Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect." Neal Jetton, director of INTERPOL's Cybercrime Directorate, goes further: "AI is automating every stage of a cyberattack, from reconnaissance and phishing to extortion and evasion." The report does not describe a future threat. It describes the current operating environment.

The surface reading of this story — the one captured in TechCabal's tweet — is that African cybercriminals are adopting AI faster than law enforcement. That is true, but it undersells the finding. The deeper point is about what AI adoption does to the economics of cybercrime, and to the specific sectors that underpin Africa's digital economy. When a fraudster can generate a synthetic identity that combines real personal data with fabricated elements and use it to bypass biometric checks, the cost of attacking a bank drops dramatically. When a deepfake video of a CEO can be produced in minutes, the social engineering playbook that once required weeks of grooming collapses into an afternoon. The report says deepfake incidents increased sevenfold between the second and fourth quarters of 2024. That is not adoption. That is acceleration.

INTERPOL based its assessment on a survey of 36 African member countries. The findings are not extrapolations from a handful of cases; they are the aggregated reporting of national law enforcement agencies across the continent. What they report is consistent: online scams are the most frequently reported form of cybercrime. Financial services, telecoms, and government institutions are the hardest hit sectors. And 72% of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa. The full report maps these patterns in detail, and the picture it paints is not one of isolated criminal actors but of organised, cross-border infrastructure.

The financial data makes the scale concrete. Cybercrime-related losses in Africa more than doubled from USD 192 million in 2024 to USD 484 million in 2026, according to the report. That is a 152% increase in two years. But even that figure is almost certainly an undercount. Underreporting is endemic in cybercrime statistics everywhere, and in markets where victims fear reputational damage or lack confidence in law enforcement, the gap between reported and actual losses is wider still. The USD 484 million figure should be read as a floor, not a ceiling.

Africa-based threat actors are also exporting their operations. The report documents cases where criminals using infrastructure spread across multiple African jurisdictions are targeting victims in Europe and North America. This is a meaningful evolution. It means the continent is no longer just a source of cybercrime victims but increasingly a base of operations for attacks that reach far beyond its borders. The implication for international cooperation is significant: no single country can address a problem that is deliberately distributed across several.

The comparison to INTERPOL's previous assessment is instructive. The 2025 Africa Cyberthreat Assessment Report warned of a sharp rise in cybercrime, including scam notifications rising by up to 3,000 per cent in some countries and increased digital sextortion. The 2026 report confirms that those warnings were not overstated — and adds a new variable. AI did not cause the rise in cybercrime. It multiplied it. The same criminal intent, augmented by automation, now produces more attacks, more convincing attacks, and attacks that are harder to attribute.

AI is compressing the attack timeline

The most consequential finding in the report is not the 55% figure itself but what it implies about speed. Traditional cybercrime operations are labour-intensive. Reconnaissance requires manual research on targets. Phishing messages had to be written by humans, often poorly, which is why poor grammar was a reliable detection heuristic. Social engineering required patience and interpersonal skill. AI collapses those timelines. Jetton's quote about AI automating "every stage of a cyberattack" is not rhetorical. It is a description of how the attack chain now works: AI-generated phishing messages that are grammatically flawless and contextually tailored; automated credential harvesting that scales across thousands of targets simultaneously; deepfake audio and video that impersonates executives and public figures with enough fidelity to convince employees to transfer funds.

The sevenfold increase in deepfake incidents between Q2 and Q4 2024 is the clearest evidence of this compression. Sevenfold growth in six months is not organic. It is what happens when a technology crosses a usability threshold — when the tools become cheap enough and easy enough that a criminal does not need specialised training to use them. The same dynamic played out with ransomware-as-a-service in other regions. Now it is happening with AI-enabled fraud in Africa.

Synthetic identities are defeating biometric verification

The report's finding on synthetic identities deserves particular attention because it strikes at the core of Africa's fintech growth story. Biometric verification — fingerprints, facial recognition, voice matching — has been marketed as the solution to identity fraud in markets where traditional identity documentation is weak. The report says criminals are now using AI-generated synthetic identities that combine real personal data with fabricated elements to bypass those biometric checks. This is not theoretical. It is documented in the cases reported by member countries.

The mechanism is sophisticated. A criminal obtains real personal data — a name, a date of birth, a national ID number — through data breaches or social engineering. AI then generates a synthetic identity around that seed: a plausible employment history, a social media presence, a voice model, a facial image that passes liveness checks. The result is an identity that does not belong to a real person but is indistinguishable from one for the purposes of Know Your Customer (KYC) compliance. For banks, mobile money operators, and identity verification firms, this is an existential challenge. Their fraud detection models were built on the assumption that identity fraud meant impersonating a real person. Synthetic identities break that assumption.

The concentration of scam centres in Southern and West Africa — reported by 72% of surveyed countries — suggests that this is not a distributed, individual-actor problem. Scam centres are organised operations with physical locations, recruitment pipelines, and division of labour. They are, in effect, cybercrime factories. AI makes those factories more productive. A single operator who previously could run a handful of romance scams simultaneously can now, with AI assistance, manage hundreds of conversations at once, each one personalised and convincing.

The hard-hit sectors are the digital economy's backbone

The report identifies financial services, telecoms, and government institutions as the sectors suffering the most. These are not peripheral actors in Africa's economy. They are the infrastructure on which everything else runs. Mobile money operators process billions of dollars in transactions across the continent. Telecoms provide the connectivity that underpins every digital service. Government institutions hold the identity and civic data that everything else depends on. When these sectors are under sustained attack, the consequences cascade through the entire economy.

TechCabal's March 2026 reporting on how AI is turning African businesses into easier cyber targets anticipated this finding. The explainer documented lower attack barriers and faster malware generation. The INTERPOL report now provides the empirical evidence. The two pieces together tell a coherent story: AI is not just enabling new types of attacks; it is lowering the cost of all attacks, which means more attackers can afford to operate, which means more victims.

Business email compromise, sextortion, and impersonation of public figures and executives are all named in the report as AI-facilitated. These are not exotic attack vectors. They are the workhorses of financial crime. AI has made them more effective, not replaced them. The criminal who once sent a poorly worded email pretending to be a CEO can now send a convincing video message in the CEO's voice. The incremental cost is near zero. The incremental success rate is substantial.

For founders and operators of fintechs, mobile money services, and digital identity platforms, the practical implication is that existing fraud controls are likely inadequate. Models trained on pre-AI fraud patterns will miss AI-generated attacks. Verification systems that check for identity theft but not synthetic identity creation will approve fraudulent accounts. Security budgets that assumed a linear increase in threat volume will need to account for exponential growth. This is not a compliance problem to be managed with a checkbox. It is a strategic risk that touches product design, customer onboarding, and trust.

For investors, the report recalibrates risk in the African fintech and telecom sectors. Companies that cannot demonstrate AI-aware fraud detection will face higher loss ratios and regulatory scrutiny. Companies that can — and that treat fraud prevention as a product differentiator — will gain market share. The USD 484 million in reported losses is a cost of doing business today. The unreported figure is almost certainly larger, and the trajectory is upward.

For regulators, the report is a call to action that existing frameworks do not address. No regulatory circular or directive is attached to this report. It is a crime-intelligence document, not a rulebook. But it makes clear that the regulatory environment needs to change. KYC requirements that were adequate for identity theft are inadequate for synthetic identities. Cross-border cooperation mechanisms that move at the speed of mutual legal assistance treaties are too slow for attacks that move at the speed of AI. INTERPOL's AFJOC initiative — the African Joint Operation against Cybercrime — is a step toward regional operational coordination, but the report implies that coordination alone is insufficient without technological capacity.

The report cannot tell us the true scale of AI-enabled cybercrime in Africa. Its data is limited to what 36 surveyed countries chose to report, and underreporting is a known and substantial bias in cybercrime statistics. The USD 484 million loss figure reflects only reported losses. The 55% AI-involvement figure reflects only cases where law enforcement had the technical capacity to identify AI as a factor. In countries with less sophisticated digital forensics, AI involvement may go undetected. The report also cannot tell us how quickly law enforcement agencies are closing the adoption gap, because it does not measure defender capability with the same granularity it applies to attacker behaviour. The comparison in the headline — criminals adopting AI faster than institutions — is true at a directional level. But without baseline data on law enforcement AI adoption, the magnitude of the gap remains unquantified.

What remains genuinely unknown is whether the 152% increase in reported losses represents a real increase in crime or an increase in reporting. Both are probably true. As awareness of cybercrime grows and reporting mechanisms improve, more losses get counted. But the deepfake data — a sevenfold increase in six months — is harder to explain away as a reporting artefact. Deepfakes require detection to be reported, and detection capabilities did not improve sevenfold in that period.

The next 12 to 24 months will be decisive. INTERPOL will presumably track whether the 55% AI-involvement figure rises, falls, or plateaus in its next assessment. The more important indicator will be whether African law enforcement agencies begin reporting successful AI-enabled prosecutions, not just AI-enabled attacks. Watch for regulatory responses from central banks and telecom regulators in Nigeria, South Africa, and Kenya — the three markets where the concentration of fintech and mobile money creates the most acute exposure. Watch also for identity verification firms adjusting their liveness detection to counter synthetic identities. The first vendor to credibly solve synthetic identity detection for African KYC will have a substantial commercial advantage. The race between attackers and defenders has never been equal. The data from this report suggests the gap is widening — and that the institutions charged with closing it are running out of time to catch up.

Share this article

Help others discover this story

https://www.techblit.com/ai-now-powers-over-half-of-africas-cybercrime-interpol-finds