AI Is Linked to 55% of African Cybercrime — Losses Doubled
INTERPOL's African Cyberthreat Assessment 2026, out today, ties AI to 55% of reported cybercrime across 36 surveyed countries, with losses up from $192M to $484M in a year. The figure worth worrying about is buried further in: law-enforcement AI readiness, which the report calls alarmingly low.
AI now features in 55% of the cybercrime reported across Africa, according to the African Cyberthreat Assessment Report 2026, published by INTERPOL today. Reported financial losses on the continent more than doubled in a year, from $192 million in 2024 to $484 million in 2025.
The report draws on survey responses from 36 African member countries, and its central claim is not that criminals discovered a new weapon. It is that they industrialised an old one. INTERPOL's framing is that cybercrime in the region has stopped looking like a series of incidents and started looking like a supply chain — borderless, specialised, and increasingly automated at every stage.
What the 55% actually describes
Neal Jetton, who runs INTERPOL's cybercrime work, puts the mechanism plainly: AI is automating every stage of an attack, from reconnaissance and phishing through to extortion and evasion. That is the useful reading of the figure. It is not a count of attacks carried out by AI systems acting alone; it is a count of reported incidents in which AI showed up somewhere in the chain — writing the lure, cloning the voice, generating the identity, or scaling the send.
Two limits are worth holding onto. First, the denominator is reported crime, and reporting capacity varies enormously between the 36 responding countries — a jurisdiction with a functioning cybercrime unit generates more data than one without, which flatters the statistics of the least-equipped places. Second, attribution of AI involvement is a judgement call made by investigators with wildly different tooling. The direction of the trend is solid. The precision of the number is not, and INTERPOL does not claim otherwise.
Four regions, four business models
The regional breakdown is where the report earns its keep, because the crime specialises by geography. East Africa is dominated by mobile money fraud and ransomware aimed at infrastructure. Central and West Africa run business email compromise and romance scams, frequently against victims in Europe and North America. Southern Africa's high connectivity makes it an attractive staging ground for global threat actors rather than only a victim pool. Scam centres — the physical call-floor operations behind much of the volume — were reported by 72% of surveyed countries, concentrated most heavily in Southern and West Africa.
Online scams were the single most reported category of cybercrime in 2025. Alongside them, partner telemetry recorded more than 600,000 digital sextortion detections during the review period, and investigators flagged a category that barely existed as a mass-market crime three years ago: synthetic identity fraud, where AI-generated personas are used to walk straight through biometric onboarding checks.
The asymmetry the report is really about
The number INTERPOL treats as most alarming is not 55%. It is the state of AI readiness inside the agencies expected to respond, which the report describes as alarmingly low, against a legislative picture it calls fragmented. Attackers are buying capability off the shelf at consumer prices. Defenders are working through procurement cycles, evidentiary standards that predate generative models, and cross-border requests that take months.
INTERPOL's recommendations follow from that gap rather than from the threat catalogue: standardised digital forensics, faster cross-border cooperation, sustained investment in AI literacy for investigators, and formal public-private arrangements instead of ad hoc ones. The report is built on exactly that last point — the telemetry comes from Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI, not from police systems.
It is not all deficit. Four coordinated operations run during the period produced more than 1,500 arrests, hundreds of seized devices, and over $100 million recovered. Those numbers show what the model looks like when the cooperation actually works. The report's argument is that it works in bursts, and the crime works continuously.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.