More than half of all reported cybercrimes across Africa are now powered by artificial intelligence. That is the headline finding from INTERPOL’s African Cyberthreat Assessment Report 2026, a 40-page document based on data from 36 African member countries that paints an increasingly alarming picture of how fast cybercrime is evolving on the continent.
Artificial intelligence is now driving 55 percent of reported cybercrimes across Africa, making attacks faster, more sophisticated, and increasingly difficult to detect, according to the report. Losses have more than doubled since 2024, rising from $192 million to $484 million.
The report warns that the continent’s rapid digital transformation, marked by more than 1.1 billion mobile subscribers in 2025, is being matched by an equally rapid evolution in cybercrime, while fragmented legislation and limited AI readiness among law enforcement agencies continue to weaken responses. Cybercrime has shifted from isolated criminal activity to an industrialised, borderless ecosystem powered by AI.
That framing is important. This is no longer about individual hackers sitting in dark rooms. INTERPOL is describing an organised, scalable criminal industry that uses the same AI tools legitimate businesses use, only pointed at victims.
East Africa has become a hotspot for mobile money fraud and ransomware attacks targeting critical infrastructure, while business email compromise and romance scams are widespread across Central and West Africa. Southern Africa has become an attractive target for international cybercriminals due to its high level of internet connectivity.

For Nigeria and West Africa specifically, the prominence of business email compromise is significant. These are attacks where criminals impersonate executives, suppliers, or trusted contacts to trick businesses into making fraudulent payments. AI has made these emails nearly indistinguishable from genuine ones.
Online scams remained the most commonly reported form of cybercrime in 2025, with criminals exploiting mobile money platforms, social media, and AI-generated content to deceive victims. Seventy-two percent of surveyed countries reported the existence of scam centres, with the highest concentration recorded in Southern and West Africa.
Scam centres, sometimes called fraud factories, are organised operations where large numbers of people are employed, sometimes through trafficking or coercion, to run scams at scale. Their concentration in West Africa is a direct concern for Nigeria.
Digital sextortion and online harassment were identified as persistent threats, driven increasingly by AI-generated deepfakes and synthetic media. According to data from TrendAI, one of INTERPOL’s partners, about 600,000 sextortion incidents were detected during the reporting period.
Six hundred thousand incidents in a single reporting period is a staggering number. Deepfake technology has lowered the barrier for creating convincing fake intimate imagery, which is then used to extort victims into paying money or providing more material.
One of the most technically alarming findings in the report concerns how criminals are bypassing identity verification systems. Cybercriminals are no longer relying solely on stolen credentials but are now creating AI-generated synthetic identities by combining genuine personal information with fabricated details. These synthetic identities have been used to bypass biometric verification systems, open bank accounts, obtain mobile loans, and register SIM cards under false identities.
For Nigeria, where SIM card registration was made mandatory precisely to reduce fraud, this finding is particularly concerning. AI-generated synthetic identities represent a direct attack on the integrity of identity verification systems that regulators have spent years building.
Africa-based threat actors are increasingly targeting victims in Europe and North America using cyber infrastructure spread across multiple jurisdictions.
This internationalisation of African cybercrime also has a consequence for Africa itself. As criminals based on the continent attract more attention from law enforcement agencies in Europe and North America, international pressure on African governments to improve cybercrime prosecution and legislation is likely to increase.
INTERPOL warned that the absence of real-time information sharing between banks, telecommunications companies, and law enforcement agencies has created significant vulnerabilities in tackling financial cybercrime.
This is a problem Nigerian cybersecurity officials have flagged repeatedly. When a bank, a telecom operator, and a police unit investigating cybercrime each sit on their own data without sharing it in real time, criminals can move money and disappear before any single institution notices the pattern.
Director of INTERPOL’s Cybercrime Directorate, Neal Jetton, described cybercrime as one of the most significant criminal threats facing Africa. He said AI is automating every stage of a cyberattack, from reconnaissance and phishing to extortion and evasion, but added that when countries work together, cybercriminal infrastructure can be identified, disrupted, and dismantled.
The report also documented real enforcement progress. Four major cybercrime operations conducted in 2025, Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel, and Operation Red Card 2.0, resulted in more than 1,500 arrests, the seizure of hundreds of electronic devices, and the recovery of over $100 million.
That is meaningful progress. But against $484 million in total losses, the gap between what was recovered and what was lost shows just how much work remains.
The report recommended the adoption of standardised digital forensic capabilities, stronger cross-border collaboration, greater investment in AI literacy for law enforcement personnel, and formal public-private partnerships to improve cybercrime prevention, detection, and response.
Despite the growing threat, the report highlighted progress in strengthening cybersecurity across the continent, disclosing that 17 African countries enacted or amended cybercrime legislation in 2025. Nigeria has been among the countries strengthening its legal framework, though INTERPOL’s findings suggest implementation and enforcement still lag significantly behind the pace of criminal innovation.
Losses doubling in a single year, 600,000 sextortion cases, AI-generated fake identities beating biometric checks, and scam centres operating openly across West Africa. Each of these findings on its own would be concerning. Together, they describe a threat that has moved well beyond what most Nigerian institutions were designed to handle. The technology criminals are using is evolving faster than the systems meant to stop them, and that gap is what INTERPOL is calling on African governments to close urgently.



