Africa’s digital revolution was supposed to be a story of liberation — mobile money reaching the unbanked, entrepreneurs bypassing broken infrastructure, young populations plugging into a global economy. That story is still being written. But running alongside it, in darker ink, is another narrative entirely: the systematic exploitation of these same digital networks by criminals who have discovered that artificial intelligence makes their work faster, cheaper and far more difficult to stop.
The numbers in INTERPOL’s African Cyberthreat Assessment Report 2026 are stark enough to demand serious attention. Artificial intelligence is now implicated in 55% of reported cybercrime cases across Africa. Financial losses linked to cybercrime more than doubled in a single year, climbing from $192 million in 2024 to $484 million in 2025. These are not rounding errors. They represent a structural shift in the threat landscape — one that African governments, by and large, are not equipped to handle.
The 40-page report draws on survey data from 36 African member countries and makes one thing plain: cybercrime has ceased to be a niche concern for technology specialists. It has become an economic and security challenge with continent-wide consequences, and it is industrialising at speed.
Consider what AI has done to the basic toolkit of the online fraudster. Business Email Compromise scams — long a menace to African businesses — have grown dramatically more convincing because AI can now generate grammatically flawless, contextually plausible emails that bypass both human scepticism and automated filters. Africa-based criminal networks are using these tools to target victims in Europe and North America, operating across multiple jurisdictions and exploiting the gaps between legal systems. The crime happens here; the money flows elsewhere; accountability dissolves in the space between borders.
Deepfakes and synthetic media have added a particularly disturbing dimension. INTERPOL’s cybersecurity partner TrendAI recorded more than 600,000 sextortion detections during the review period — cases in which fabricated intimate imagery is weaponised for harassment and extortion. This is not abstract digital harm. It destroys reputations, livelihoods and, in some cases, lives.
The geography of organised cybercrime on the continent is also becoming clearer. 72% of surveyed countries reported the presence of organised scam centres, with the highest concentrations in Southern and West Africa. These are not lone actors working from bedrooms. They are structured operations, often running across multiple countries, with supply chains, hierarchies and, increasingly, AI-powered tools that reduce the skill barrier for entry-level criminals.
Neal Jetton, Director of INTERPOL’s Cybercrime Directorate, put it plainly: AI is now automating every stage of a cyberattack, from initial reconnaissance and phishing through to extortion and evasion of detection. That is a qualitative change in the nature of the threat, not merely a quantitative one.
There have been operational successes worth acknowledging. Four major joint operations conducted in 2025 — Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel and Operation Red Card 2.0 — resulted in more than 1,500 arrests, the seizure of hundreds of electronic devices and the recovery of over $100 million. These are meaningful results, and they demonstrate what coordinated cross-border policing can achieve when the political will exists.
But arrests are a lagging indicator. They tell you what happened after the crime. The deeper problem is structural, and INTERPOL does not shy away from naming it. Africa has more than 1.1 billion mobile subscribers — a vast digital population — yet cybercrime legislation across the continent remains fragmented, and AI readiness within law enforcement agencies is, by the report’s own assessment, alarmingly low. Criminals are running rings around institutions that lack the tools, training and legal frameworks to respond effectively.
Legislative reform, INTERPOL argues, will not be sufficient on its own. What is needed is a combination of standardised digital forensic capabilities, genuine cross-border collaboration, serious investment in AI literacy for law enforcement personnel, and formal partnerships between governments, financial institutions, technology companies and telecoms providers. The report also calls for improved digital literacy among the general public — because the most sophisticated AI-generated phishing email is still defeated by a citizen who knows what to look for.
The African Cyberthreat Assessment 2026 is part of INTERPOL’s African Joint Operation against Cybercrime initiative, funded by the United Kingdom’s Foreign, Commonwealth and Development Office, with data contributed by Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI.
The uncomfortable reality is this: the same AI tools that defenders are deploying to detect threats and monitor networks are available to criminal organisations, which are adopting them with equal enthusiasm and considerably fewer constraints. This is not a problem that will plateau. As AI capabilities advance, the gap between a well-resourced criminal network and an under-equipped national cybercrime unit will widen — unless African states treat this as the strategic priority it plainly is. The digital economy cannot be built on a foundation that criminals are actively mining. The time to close the gap is now, not after the next set of losses has doubled again.

