A new report by Interpol, the African cyberthreat assessment report 2026 has revealed that artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect.
According to the 40-page report which relied on survey data from 36 African countries, the bulk of data breaches was observed in South Sudan, South Africa, Nigeria, and Namibia, between January 2024 and September 2025.
It noted that ransomware incidents were similarly prevalent across South Africa, Nigeria, Namibia, Senegal, and Zambia, with attackers increasingly targeting healthcare institutions, utility providers, and public service portals to maximise disruption and extortion potential.
Business email compromise (BEC) involves attackers tricking workers into sending money or private data by pretending to be bosses or trusted partners.
West Africa was observed as the most active region for BEC detections.
“Ransomware detections in 2025 provided by TrendAI reached record levels in Cabo Verde, with 16,997 detections, the second highest in Africa, while Nigeria recorded 5,822, reflecting the country’s dual role as an origin and target of cybercrime,” the report reads.
The report further noted that the sophistication of these BEC campaigns have increased dramatically, with AI now used to generate highly convincing email correspondence that mimics executive tone, internal jargon, and signature styles with near-perfect fidelity.
In 2025, TrendAI data indicated that 70 percent of BEC detections originated in South Africa and 29 percent from Nigeria.
The report described BEC as the financial engine of transnational cybercrime.
Microsoft-identified threat actors based in South Africa, active since 2017, primarily target US-based enterprises and use compromised email accounts and money mule networks to divert funds to offshore accounts.
Interpol also said threat actors based in Nigeria, active since 2021, have become central to international money laundering operations, routing illicit proceeds through crypto exchanges, shell companies, and mobile payment platforms.
Mali recorded the highest sextortion detections in West Africa, with 3,494 incidents, suggesting growing infrastructure for automated blackmail campaigns.
The crypto economy in the region was valued at $205 billion in transactions between July 2024 and July 2025 and became a magnet for fraud, the report said. Of this figure, Nigeria accounted for $92 billion.
South Africa, Kenya, and Nigeria were also among countries with the highest vulnerabilities for data breaches.
In 2024, the National Identity Management Commission (NIMC) enforced a policy mandating that every SIM card be linked to a unique and verifiable national identification number (NIN).
The Interpol said while the policy significantly reduced fraud, cybercriminals adapted rapidly by exploiting gaps in KYC enforcement and registering SIM cards under false names with the help of AI.






