Summary
- INTERPOL’s assessment draws on a survey of 36 African member countries and partner datasets.
- The report links AI to expanding scams, synthetic identities, business email compromise, deepfakes, and automated social engineering.
- Africa-based actors are targeting European organisations through infrastructure and financial channels spread across several jurisdictions.
INTERPOL says artificial intelligence featured in 55 per cent of the cybercrime cases covered by its latest African assessment, as criminal groups automate social engineering, build synthetic identities, and run cross-border fraud through infrastructure distributed across several jurisdictions.
The international policing organisation’s African Cyberthreat Assessment Report 2026 draws on survey responses from 36 member countries and datasets supplied by technology, telecommunications, financial, and security partners. It describes cybercrime as an increasingly industrialised ecosystem rather than a collection of isolated national incidents.
Online scams remained the most commonly reported category during 2025. INTERPOL said criminals are using AI to increase the speed, volume, and plausibility of phishing, credential theft, extortion, and other forms of social engineering.
The report also identifies business email compromise as a significant cross-border threat. Africa-based operators are targeting organisations in Europe and North America while using hosting, communications, financial accounts, and other infrastructure in several countries, complicating attribution and evidence collection.
AI-generated correspondence allows attackers to produce more convincing business messages and adapt language rapidly for different victims. The underlying fraud still depends on access to payment processes, trusted identities, invoices, supplier relationships, or executive authority, but the cost of creating and varying the lure has fallen.
INTERPOL said criminals are also combining genuine personal information with fabricated elements to create synthetic identities. Those identities can be used to open bank accounts, register mobile telephone numbers, seek loans, and move proceeds through financial systems without relying on a single stolen identity.
Deepfakes and synthetic media are contributing to digital extortion and harassment, while automated techniques support reconnaissance, phishing, and attempts to evade detection. The report cites approximately 600,000 sextortion detections from one partner dataset, although that figure should not be read as a count of police-confirmed cases or unique victims.
Reported cybercrime losses in the datasets cited by INTERPOL increased from $192 million to $484 million between 2024 and the latest assessment. Differences in reporting, policing capacity, victim behaviour, and national measurement mean those figures do not provide a complete estimate of the economic impact across the continent.
The report found that 72 per cent of surveyed countries reported the presence of scam centres, with concentrations in Southern and West Africa. Such facilities combine recruitment, coercion, financial fraud, telecommunications, and online platforms, and their operations may target victims far beyond the country in which the workers or infrastructure are located.
Regional patterns differ. INTERPOL describes East Africa as a centre of mobile-money fraud and ransomware affecting infrastructure, Central and West Africa as heavily exposed to business email compromise and romance fraud, and Southern Africa’s high connectivity as attractive to criminal and other threat actors.
The institutional constraints are as important as the attack techniques. INTERPOL found fragmented cybercrime legislation, limited AI readiness in law-enforcement bodies, and inadequate real-time information exchange between banks, telecommunications providers, platforms, and investigators.
Those gaps allow money, accounts, domains, telephone numbers, and identities to move faster than the legal processes used to preserve evidence or stop transactions. European organisations affected by Africa-linked fraud may need investigators and financial institutions in several countries to act before infrastructure is abandoned or funds are transferred again.
New laws alone do not resolve shortages in digital forensics, cross-border procedure, specialist personnel, judicial capacity, or access to private-sector data.
The report’s 55 per cent figure reflects reported cybercrime within the evidence assembled for the assessment, not a measurement of every offence committed across Africa. Countries with stronger reporting systems may appear more exposed because incidents are more likely to be recorded, while under-resourced jurisdictions may contribute less data despite facing substantial criminal activity.
INTERPOL’s assessment nevertheless shows why African cybercrime cannot be treated as a regional issue alone. Business email compromise, payment fraud, synthetic accounts, and scam infrastructure operate through global technology and financial systems. European exposure is created by the cross-border transaction, not merely by the location of the offender.




