Africa’s financial institutions, telecommunications companies and government agencies are facing an increasingly coordinated wave of cyberattacks, with mobile-money fraud, ransomware and business email scams emerging as the continent’s biggest digital threats, according to INTERPOL’s African Cyberthreat Assessment Report 2026.
The report warns that cybercrime in Africa has evolved from isolated attacks into a transnational criminal enterprise exploiting weak regulation, fragmented law enforcement and the rapid expansion of digital financial services. Financial services, telecommunications and public institutions remain the sectors most affected, while attacks on utilities and healthcare systems have disrupted essential services and exposed sensitive personal data.
The growing use of mobile-money platforms, which has accelerated financial inclusion across the continent, has also created new vulnerabilities, particularly in countries where customer verification standards are inconsistently enforced, according to INTERPOL.
“Cybercriminal networks operate across borders with minimal friction, leveraging diverging legal jurisdictions, under-resourced law enforcement, and limited cross-border information-sharing mechanisms,” the report said.
West Africa emerged as the continent’s epicenter for business email compromise and online fraud schemes, while East Africa has become a hub for mobile-money fraud and ransomware attacks targeting critical infrastructure. Southern Africa, the continent’s most digitally connected region, recorded the highest concentration of ransomware incidents.
Mobile-money fraud was identified as the most prevalent online scam in Africa, with 97% of countries surveyed reporting cases. In Ghana alone, citizens lost $1.3 million in the first quarter of 2025, while Kenya uncovered more than 123,000 fraudulent SIM cards used in SIM-swap attacks that drained an estimated $3.8 million from mobile wallets.
The report said cybercriminals are increasingly exploiting artificial intelligence to create synthetic identities capable of bypassing know-your-customer protocols, opening bank accounts and securing loans under false identities. Fraud hotspots have shifted toward countries such as Cameroon, Mali and Tanzania, where gaps in customer verification remain widespread.
Business email compromise, a form of fraud in which criminals impersonate corporate executives to redirect payments, has also become more sophisticated with the use of AI-generated messages that mimic writing styles and internal corporate language. According to the report, 70% of such attacks originated in South Africa and 29% in Nigeria.
One case uncovered during INTERPOL’s Operation Sentinel involved a Senegal-based network attempting to divert $7.9 million from a petroleum company using fraudulent emails. Authorities managed to freeze the destination account, highlighting the increasingly international nature of cybercrime operations originating from Africa.
Ransomware attacks have also expanded beyond financial extortion to target critical infrastructure. South Africa accounted for 92% of all ransomware detections on the continent in 2025, with attacks disrupting institutions including the South African Weather Service and national airlines. In Nigeria, a ransomware attack on the customs service disrupted cargo clearance operations at major ports and generated an estimated $18 million in storage costs and delays.
In Uganda, a suspected ransomware attack on the country’s electricity transmission company compromised monitoring systems for the national grid, while Namibia suffered multiple attacks on telecommunications infrastructure.
INTERPOL said underreporting remains one of the biggest obstacles to combating cybercrime, with 89% of member countries citing the absence of formal reporting mechanisms, concerns over reputational damage and a lack of forensic capabilities as major barriers. Only Nigeria, Kenya, South Africa and Mauritius require organizations to disclose cyber incidents within 72 hours, while Ghana mandates reporting within 24 hours of detection.
The report estimates that 72% of African countries have identified scam centers operating within their borders, many of them linked to organized crime, human trafficking and money laundering networks. Criminal groups are increasingly using artificial intelligence, social media and cryptocurrency platforms to expand their operations across borders.
INTERPOL warned that the continent’s fragmented regulatory systems and limited cooperation between banks, telecommunications companies and law enforcement agencies have created opportunities for cybercriminals to exploit gaps in enforcement.
“The African cyberthreat landscape is no longer defined by isolated incidents conducted by threat actors, but by a coordinated, transnational criminal ecosystem,” the report said.
