Artificial intelligence is now enabling 55 percent of reported cybercrimes across Africa, making attacks faster and harder to detect, INTERPOL said on Monday, as losses more than doubled to USD 484 million in two years.
The African Cyberthreat Assessment Report 2026, based on survey data from 36 member countries, found that cybercrime has evolved from isolated incidents into an “industrialised, borderless ecosystem,” the global police body said.
AI-facilitated scams, credential harvesting and automated social engineering campaigns have driven the surge in financial losses, which have jumped from USD 192 million since 2024, according to the 40-page report.
Africa’s digital transformation is expanding rapidly, with more than 1.1 billion mobile subscribers recorded in 2025, but cybercrime legislation remains fragmented, and AI readiness among law enforcement agencies is “alarmingly low,” INTERPOL said.
Regional hotspots
East Africa has emerged as a hub for mobile money fraud and ransomware targeting infrastructure, while business email compromise (BEC) and romance scams were prolific in Central and West Africa, the report said.
Southern Africa’s ultra-high connectivity makes it a magnet for global threat actors seeking maximum disruption, according to INTERPOL.
Online scams remained the most reported type of cybercrime in 2025, with attackers leveraging mobile money platforms, social media and AI to reach targets, the report said.
Seventy-two percent of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa.
AI-powered threats
Digital sextortion and online harassment, often facilitated by AI-generated deepfakes and synthetic media, remained pervasive, with approximately 600,000 sextortion detections recorded by TrendAI, one of several partners working with INTERPOL.
The sophistication of BEC schemes has increased dramatically, with AI used to generate highly convincing email correspondence, the report said.
Africa-based threat actors have targeted victims in Europe and North America using infrastructure located across multiple jurisdictions.
Criminals have moved beyond stealing existing credentials to creating entirely synthetic identities, the report warned.

Combining real personal data with fabricated elements, these AI-generated digital personas can bypass advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names.
“Cybercrime has emerged as one of the most significant criminal threats to the region,” Neal Jetton, director of INTERPOL’s Cybercrime Unit, said in the report.
“AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion.
“However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled.”
The report noted some progress, with 17 countries enacting or amending cybercrime legislation in 2025, including the launch of an online reporting platform in Senegal aimed at enhancing response to online violations affecting children.
Four major INTERPOL-coordinated cybercrime operations – Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel and Operation Red Card 2.0 – collectively led to more than 1,500 arrests, the seizure of hundreds of devices and the recovery of over USD 100 million, INTERPOL said.
The report called for standardised digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal public-private partnerships to support effective prevention, detection and response.
It also warned that the absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud.
Trending 






