*Nigeria emerges as a major crypto market
*Accounts for $92bn in transactions
*Customs ransomware attack causes $18m in storage fees
Cybercrime-related losses across Africa rose rapidly from $192 million in 2024 to $484 million in 2025, as criminals increasingly deployed artificial intelligence, mobile platforms and cross-border networks to scale online attacks, according to the 2026 African Cyberthreat Assessment Report by the International Criminal Police Organisation, INTERPOL.
The report identified online scams as the most reported form of cybercrime on the continent, while ransomware, business email compromise, data breaches, financial fraud and digital sextortion continued to threaten individuals, businesses and critical infrastructure.
Artificial intelligence has further complicated the threat landscape, with criminals using generative AI to automate attacks, impersonate individuals, create convincing fraudulent content and evade traditional security controls.
Based on its assessment of the continent’s cybercrime landscape, INTERPOL identified seven major threats shaping Africa’s digital security environment.
Ransomware moves beyond financial extortion
Ransomware is increasingly being used not only to demand payments from victims but also to disrupt public services and critical infrastructure, according to INTERPOL.
The most significant incidents recorded in 2025 were concentrated in Southern and West Africa, where outdated systems, underfunded cybersecurity units and limited reporting continued to expose organisations to attacks.
South Africa accounted for 92 per cent of ransomware detections in Africa, based on TrendAI data cited by INTERPOL.
Nigeria also featured prominently, following a ransomware incident targeting the Nigeria Customs Service in August 2025 that disrupted cargo clearance operations at major ports. The disruption was estimated to have resulted in $18 million in storage fees and significant delays to import processes.
Uganda’s Electricity Transmission Company Limited also experienced a suspected ransomware attack in August 2025, compromising systems used to monitor the national power grid. Services were restored through backup protocols.
Namibia recorded two separate incidents involving its telecommunications sector. One attack compromised the customer database of a national telecommunications provider, while another reportedly disrupted core network functions at Paratus Telecom.
The incidents illustrate the growing shift in ransomware from a tool of financial extortion to one capable of disrupting essential services and economic activity.
Business email compromise turns trust into a weapon
Business email compromise, or BEC, continues to exploit one of the most vulnerable parts of digital security: human trust.
Rather than directly attacking a computer system, criminals compromise email accounts or impersonate senior executives to manipulate employees, particularly those responsible for finance, procurement and payroll, into transferring money or changing payment details.
The emergence of generative AI has made such attacks more difficult to detect by allowing criminals to produce highly convincing correspondence that mimics the language and communication style of executives.
TrendAI data cited by INTERPOL showed that South Africa accounted for 70 per cent of BEC detections in Africa in 2025, while Nigeria accounted for 29 per cent.
The report highlighted a case uncovered during INTERPOL’s Operation Sentinel involving a Senegal-based attempt to divert $7.9 million from a petroleum company.
Authorities succeeded in freezing the destination account, but the incident demonstrated how cybercriminal networks operating from Africa can target businesses in Europe and North America while using infrastructure and financial networks spread across multiple jurisdictions.
According to INTERPOL, criminals typically begin by identifying employees involved in payments before using phishing or credential theft to compromise accounts. They then send seemingly legitimate messages requesting urgent changes to payment information or transfers.
Online scams become organised criminal enterprises
Online scams have evolved from isolated phishing attempts into highly organised operations increasingly linked to dedicated scam centres and transnational organised crime.
INTERPOL said 72 per cent of surveyed African countries reported the presence of scam centres, with Southern and West Africa recording the highest concentration.
Mobile money fraud was the most prevalent scam reported in the survey, with 97 per cent of responding countries identifying it as a significant threat.
Kenya detected 123,000 fraudulent SIM cards in 2025, providing criminals with a means of conducting SIM swaps and accessing mobile wallets.
In Ghana, citizens lost $1.3 million to such fraud in the first quarter of 2025, while Tanzania recorded a 19 per cent reduction in attempts after strengthening SIM registration enforcement.
Loan and microcredit scams also expanded across West and Central Africa. Fraudulent fintech applications were used to harvest victims’ personal information under the guise of providing quick loans, with victims subsequently subjected to harassment and extortion.
Cryptocurrency has become another important channel for fraudulent schemes.
INTERPOL estimated cryptocurrency transactions in the region at $205 billion between July 2024 and July 2025, with Nigeria accounting for $92 billion.
Criminals have exploited growing interest in digital assets through fake investment platforms, fraudulent trading schemes and deepfake endorsements.
In one major operation, INTERPOL’s Operation Serengeti 2.0 dismantled a Zambia-based network accused of causing $300 million in losses and affecting about 60,000 victims.
Digital sextortion is being amplified by AI
Digital sextortion has also emerged as a growing threat, with criminals combining social media, manipulated content and AI-generated material to target victims.
TrendAI recorded about 600,000 sextortion detections in Africa in 2025. South Africa accounted for 30 per cent, followed by Kenya at 13 per cent, Côte d’Ivoire at 11 per cent, Ethiopia at 8 per cent and Angola at 4 per cent.
INTERPOL said criminals increasingly establish relationships with victims on social media before moving conversations to private messaging platforms, where they use manipulated or fabricated material to exert pressure.
The growing accessibility of AI tools has made the threat more difficult to combat by allowing criminals to produce convincing synthetic content using publicly available photographs.
The report also highlighted the growing targeting of young people. Meta data cited by INTERPOL showed that 635,000 accounts on Instagram and Facebook were removed in 2025 for exploiting children, a tenfold increase from 2023.
INTERPOL warned that sextortion is becoming increasingly scalable as criminals combine social media, AI-generated content and automated communication tools.
Data breaches are fuelling wider cybercrime
Data breaches are increasingly serving as the foundation for other forms of cybercrime, providing criminals with personal and financial information that can subsequently be used for identity theft, fraud, ransomware and business email compromise.
The Shadowserver Foundation identified more than 6,000 exploitable vulnerabilities across Africa in 2025, with the highest concentrations in South Africa, Kenya and Nigeria.
South Africa accounted for 43.6 per cent of detected vulnerabilities, followed by Kenya at 11.9 per cent and Nigeria at 9.1 per cent.
The vulnerabilities largely involved outdated or unpatched routers, vulnerable VPNs and misconfigured web-based systems.
In Namibia, a telecommunications provider suffered a breach that exposed about 500,000 personal and financial records. The incident was reportedly linked to an unsecured administrative portal accessible from the public internet.
INTERPOL also recorded a 62 per cent year-on-year increase in African-origin data appearing on dark web forums.
The stolen information included identity documents, SIM card PINs, banking credentials and mobile money account details, creating opportunities for criminals to reuse compromised data long after the original breach.
Financial fraud and synthetic identities threaten digital trust
Cybercriminals are increasingly moving beyond stealing existing identities to creating synthetic ones using genuine personal information combined with fabricated details.
According to INTERPOL, these identities can be used to open bank accounts, obtain digital loans and register SIM cards under false names.
Nigeria’s NIN-SIM policy helped reduce certain forms of fraud in 2024, but criminals adapted by shifting activity towards countries and financial systems where identity verification and KYC controls remain weaker.
SIM swap fraud is another growing vulnerability because control of a victim’s telephone number can provide access to financial accounts and mobile money services.
Kenya recorded a 327 per cent increase in SIM swap fraud in 2025, according to the report.
Money mule networks have further complicated the fight against financial cybercrime. Criminals recruit individuals, sometimes through fake job advertisements, to receive and transfer illicit funds on their behalf.
INTERPOL cited a 2025 survey showing that almost 77 per cent of fraud-exposed individuals in Africa were aware of money muling, but only 12 per cent understood its legal consequences or recognised that participating could amount to criminal complicity.
AI is making cybercrime faster and more scalable
Artificial intelligence is increasingly acting as a force multiplier for cybercriminals, allowing attacks that previously required significant technical expertise to be conducted faster and on a much larger scale.
INTERPOL’s member country survey found that 55 per cent of cybercrime cases in 2025 involved AI to some extent. Of this figure, 47 per cent involved occasional use of AI, while 8 per cent involved frequent use.
Criminals are deploying AI across different stages of the attack process, including identifying victims, creating phishing messages, producing deepfakes, generating synthetic identities and adapting malicious software.
Deepfake incidents increased sevenfold across Africa between the second and fourth quarters of 2024, according to data cited in the report.
AI-generated audio and video have been used to impersonate government officials, corporate executives and public figures in fraudulent investment schemes.
The report also highlighted emerging malware capable of using generative AI to adapt malicious code, potentially making conventional signature-based detection less effective.
However, law enforcement agencies are struggling to keep pace with the technology.
Only 33 per cent of agencies surveyed said they were using AI for threat detection, while 31 per cent were using it for digital forensics and open-source intelligence analysis.
Only 8 per cent of intelligence analysts had advanced AI expertise, while 92 per cent of agencies identified a lack of technical expertise as the primary barrier to adopting AI tools.
Calls for stronger continental response
With cybercriminals increasingly operating across borders and using AI to automate their activities, INTERPOL called for African countries to strengthen both national capabilities and continental cooperation.
The organisation recommended greater investment in national cybercrime units, including digital forensics laboratories, malware analysis platforms and AI-powered threat detection systems, as well as specialised tools for mobile forensics, cryptocurrency tracing and deepfake identification.
It also called for dedicated teams focused on AI-enabled crime, crypto-asset investigations and cyber-enabled human trafficking.
Beyond technology, INTERPOL identified cross-border cooperation as a major weakness in Africa’s cybercrime response.
It recommended that countries harmonise cybercrime definitions, evidence preservation procedures and data-sharing protocols, while establishing a 24-hour regional contact network to facilitate the rapid exchange of digital evidence during major cyber incidents.
The organisation also called for stronger cooperation among law enforcement agencies, national Computer Emergency Response Teams, telecom operators, banks and fintech companies.
Under the proposed approach, mobile money operators and fintech platforms would integrate real-time fraud alerts with national cybercrime units, while telecom operators would strengthen identity verification during SIM registration and customer onboarding.
INTERPOL further urged African countries to strengthen and harmonise cybercrime laws and establish expedited procedures for obtaining electronic evidence across borders, particularly in cases involving ransomware, BEC and deepfake-enabled crimes.





