INTERPOL released its African Cyberthreat Assessment Report 2026 on August 3, delivering what the organization described as a continent-scale reckoning: artificial intelligence is enabling 55 percent of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect. The 40-page report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialized, borderless ecosystem. The financial arithmetic is blunt. Since 2024, cybercrime-related losses have more than doubled, from $192 million to $484 million, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.
The mechanics detailed in the report leave little ambiguity about how that scaling has occurred. "Cybercriminals are now deploying AI-powered tools to automate phishing campaigns, generate convincing deepfakes for identity fraud and social engineering, create synthetic identities for financial fraud, and evade detection by traditional signature-based security systems," the report notes. More than 600,000 sextortion detections were recorded by cybersecurity partner TrendAI during the review period. Regional patterns diverge sharply: East Africa emerged as a hub of mobile money fraud and infrastructure-targeted ransomware, while business email compromise and romance scams targeting both corporate and individual victims were prolific in Central and West Africa. Three-quarters of participating countries reported the presence of scam centers, and victims of business email compromise and scams are most likely to be located in Europe and North America, underscoring that the damage is not confined to the continent where the attacks originate.
Neal Jetton, director of INTERPOL's Cybercrime Directorate, framed the problem in categorical terms. "Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion. However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled." INTERPOL pointed to evidence that cooperation can bite back: Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel, and Operation Red Card 2.0 resulted in more than 1,500 arrests, the seizure of hundreds of electronic devices, and the recovery of over $100 million.
Skeptics and legal scholars raise a structural objection that the arrest tallies do not resolve. Critics have voiced concerns that the rapidly changing nature of AI technology outpaces existing foundational documents such as the African Union Convention on Cyber Security and Personal Data Protection; since this instrument relies on early 2010s legal definitions, a critical gap exists when addressing modern AI-driven social engineering, which lacks explicit coverage under the original texts. The enforcement gap is just as stark at the operational level: 92 percent of agencies lack technical know-how in AI, leaving enforcement fragmented and reactive, while only 8 percent of intelligence analysts possessed advanced AI expertise. With Africa recording more than 1.1 billion mobile subscribers in 2025, the report noted that while the continent's digital transformation is accelerating, cybercrime legislation remains fragmented and AI readiness among law enforcement agencies is still alarmingly low, a combination that analysts say makes the region a test case for what happens everywhere else once criminal AI tooling outpaces institutional response.
Put plainly: if AI-enabled fraud has already cleared 55 percent of reported crime on a continent where enforcement capacity is thin and legal frameworks are a decade out of date, the policymakers in Washington and Brussels who are still debating AI liability thresholds are watching the wrong clock.