TL;DR: INTERPOL's 40-page African Cyberthreat Assessment Report 2026, published on August 3, finds AI is now tied to 55% of reported cybercrime across 36 surveyed African countries. Reported financial losses more than doubled, from $192 million in 2024 to $484 million in 2025. The specific privacy and surveillance worry: AI-generated synthetic identities are now bypassing the biometric KYC checks that African banks and mobile-money providers rely on to verify customers. INTERPOL Cybercrime Director Neal Jetton: "AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion."[1][2][3]

The Headline Number: 55%

More than half of all cybercrime reported across Africa in 2025 was AI-enabled, according to INTERPOL's report. The 40-page assessment draws on survey data from 36 African member countries and lists automated phishing, ransomware, social engineering, credential harvesting, business email compromise (BEC), romance scams, digital sextortion, and synthetic identity creation among the threats that have scaled because of AI.[1][2]

Reported financial losses have more than doubled since 2024, from $192 million to $484 million. About 600,000 sextortion attempts were logged by TrendAI, one of the data partners listed in the report. Seventy-two percent of surveyed countries said organized scam centers were operating on their territory. Seventeen African countries enacted or amended cybercrime legislation in 2025.[1][3]

The capacity gap is the other half of the story. According to the report, 92% of African law-enforcement agencies lack staff with technical AI know-how, and only 8% of intelligence analysts have advanced AI expertise. INTERPOL's recommended fix is investment in AI literacy among officers, standardized digital-forensic capabilities, and formal public-private partnerships for prevention, detection, and response.[1][3]

The Privacy Hook: Synthetic IDs Beat Biometric KYC

The piece of the report that touches this site's readers most directly is the section on synthetic identity creation. INTERPOL documents that criminals in Tanzania and Kenya combined stolen personal data with deepfaked biometric faces to create identities that passed the verification systems banks and mobile-money providers use to confirm a customer is real.[1][3]

Those synthetic identities were used to open bank accounts, secure mobile loans, and register SIM cards. The INTERPOL report treats this as an identity-infrastructure problem, not just a fraud one: a synthetic ID that survives biometric KYC is a working passport into the bank, the mobile-money network, and the telecom. Africa is the testing ground, but the same recipe travels.[1][3]

The same playbook extends to corporate fraud. INTERPOL documents a case in which criminals used voice and video cloning to impersonate South African Reserve Bank Governor Lesetja Kganyago, persuading victims to transfer funds to fake investment platforms. SARB is the institution that sets South African interest rates. The impersonation did not just steal money; it eroded public trust in a central bank.[2]

Where the Attacks Cluster

The report sorts the African threat landscape by region. East Africa is the hub of mobile money fraud and infrastructure-targeted ransomware. Central and West Africa remain the center of business email compromise and romance scams, with victims most often in Europe and North America. Southern Africa, with its ultra-high connectivity, is the most likely host for scam centers, alongside West Africa.[1][3]

The named ransomware strains hitting African healthcare systems, power utilities, and educational institutions include Qilin and Akira. Cybercrime-as-a-Service is now distributed through dark-web platforms, meaning affiliates can rent the tooling without building it themselves.[3]

Online scams were the most reported cybercrime type in 2025. The attack chain leans on AI to scale phishing lures, generate convincing BEC email correspondence, and run automated social-engineering campaigns that previously required a human operator per victim.[1][3]

The Operations That Have Been Working

Four INTERPOL-coordinated operations ran across the continent in 2025 and early 2026. Operation Sentinel recovered $3 million and led to 574 arrests in December 2025. Operation Red Card 2.0, in February 2026, recovered $4.3 million and led to 651 arrests. Operation Contender 3.0 arrested 260 suspected scammers in September 2025. Operation Serengeti 2.0 dismantled large-scale cybercrime networks in August 2025. Across the four, INTERPOL reports more than 1,500 arrests and more than $100 million recovered.[1][2]

The reporting backbone for the assessment is funded by the United Kingdom's Foreign, Commonwealth and Development Office under the African Joint Operation against Cybercrime (AFJOC) initiative. INTERPOL's data partners for the report are Fortinet, Mastercard, the Shadowserver Foundation, S2W, and TrendAI.[1]

That partnership list is itself a signal. Mastercard sits at the intersection of payment fraud and identity verification, the exact layer the synthetic-identity attacks target. The fact that a payment network is contributing data to an INTERPOL threat report shows where the private-sector exposure is concentrated.[1]

What to Watch

Synthetic-identity fraud outside Africa. The same deepfake-plus-stolen-data recipe that passes KYC in Kenya can be replayed against any biometric onboarding system that relies on a still photo or a short video clip. Watch for similar disclosures from US and European banks.[1][3]

SARB-style central-bank impersonations. Voice cloning that fools victims into thinking they are talking to a central bank governor is not a one-off. Expect regulators in other countries to publish consumer warnings and to push for stronger customer-verification protocols on investment platforms.

The 17-country legislative wave. Seventeen African countries enacted or amended cybercrime laws in 2025. Watch whether those laws land as substantive reforms or as broad criminalization statutes that also chill security research and anonymous reporting, as EFF and civil-society groups have warned about in other jurisdictions.[1]

The 92% capacity gap. The report's most uncomfortable finding is that 92% of African law-enforcement agencies lack AI-literate staff. That gap is what turns a manageable fraud wave into an entrenched one. INTERPOL's recommendation is training; the test is whether that training is funded, retained, and matched against adversaries that ship new models every quarter.[1][3]

Sources

  1. INTERPOL: "INTERPOL report finds AI linked to more than half of cybercrime in Africa" (August 3, 2026)
  2. JURIST, Cecilia Akoko Attiogbe Atayi: "INTERPOL report finds AI linked to over half of cybercrime in Africa" (August 4, 2026)
  3. Infosecurity Magazine, Phil Muncaster: "AI Accounts for Over Half of Cybercrime in Africa, Says INTERPOL" (August 4, 2026)