INTERPOL Cautions Africa to Advance Transnational Government Cybersecurity     

0
##csafri0

The swift expansion of digital technology in Africa, has now come to a crucial and dangerous turning point. This development is caused by a sharp increase in mobile financial services, digital onboarding and fintech platforms, in which the total accumulated data shows that the continent had over 1.1 billion mobile subscribers by 2025. At the same time, this highly populated digital environment has resulted in a much larger and more vulnerable area for cyberattacks.

In its 2026 African Cyberthreat Assessment Report, published on August 3, 2026, INTERPOL issued an extreme warning alarm that Artificial Intelligence (AI) has been put to destructive use, currently accounting for 55% of all cybercrimes reported in Africa. Between 2024 and 2025, losses due to cybercrime on the continent more than doubled, amassing from $192 million to $484 million, indicating rise of about 152.08%. The direct economic damage suffered across Africa, is estimated to have amounted to at least $5 billion in 2025 alone.

Some African countries, especially South Africa, are now at the forefront of an invisible global conflict, as cybercriminals use generative AI to automate all stages of their attacks, from target reconnaissance and tailored phishing, to data extortion and defensive evasion.

INTERPOL with other cybersecurity experts from various regions, have identified several key threatening methods that are changing the nature of digital risk, which are enabled by AI. Also, the creation of synthetic identities, is the most difficult and dangerous threat facing the continent’s digital economy. In this case, instead of stealing by using the credentials of a real person as in traditional identity theft, synthetic identity fraud builds a composite persona. In clear terms, the fraudster obtains genuine biographical details such as bank verification numbers in Nigeria or national identification numbers in South Africa, from data breaches or leaks on the dark web, and then combine them with AI-generated components, such as deepfake biometric faces or fabricated contact information to carry out impersonated transaction.

In 2024 the rates of synthetic identity fraud went up by 481% in South Africa and in Nigeria it hit 192%. Currently, Southern Africa is experiencing a severe biometric threat, because 87% of all failed biometric verification attempts in the region, are as a result of AI-assisted impersonation and spoofing. These organised syndications, take advantage of the systemic weakness of registering SIM cards in false names to open fraudulent bank accounts and obtain untraceable mobile loans.

The threat came to a peak in South Africa recently, when the South African Reserve Bank (SARB) released an urgent public alert about a deepfake video that copied both the voice and appearance of SARB Governor Lesetja Kganyago, to promote a fraudulent investment scheme. Deepfake campaigns have also affected President Cyril Ramaphosa of South Africa, renowned business woman – Patrice Motsepe, sports star – Siya Kolisi, etc., with the aim of exploiting the public’s trust to legitimize financial scams. Over the past years, there has been an alarming 1200% upsurge in deepfake-related scams in South Africa, with the banking and fintech industries being the most affected.

Previously, African-based phishing operations could usually be spotted because of spelling mistakes, awkward wording and grammatical oddities. Currently, generative AI has removed these linguistic warning signs. Now fraudsters use artificial intelligence to produce perfectly written, contextually appropriate and culturally suitable business correspondence. According to Microsoft’s digital defense report, it states that these AI tech-aid, have allowed local gangs to carry out very successful Business Email Compromise (BEC) scams, directed at international companies in Europe and North America, making up 21% of all identity-compromise outcome attacks in 2025.

The main structural weaknesses, taken advantage of by cybercriminals, is the growing gap between the rapid uptake of technology and the slow response in terms of regulation and enforcement by state institutions. The INTERPOL report reveals a serious treaty gap and marked lack of capabilities among African governments:

  • The existing legal treaties: the Malabo Convention of the African Union, which is supposed to be the main treaty for regulating digital security on the continent, was drawn up in 2014 and did not come into enforcement until June 2023, after a delay of nine years; the core provisions of this treaty are based on definitions from the early 2010s; and do not include specific legal coverage for modern threats caused by AI, such as fraud enabled by deepfakes, the creation of synthetic identities and automated social engineering.
  • The gap in law enforcement capabilities: the level of readiness of African law enforcement agencies when it comes to AI, is remarkably low. Ninety-two per cent of these agencies do not possess the necessary technical knowledge, forensic equipment and digital resources to analyses, or investigate cybercrimes that are enabled by AI. Throughout the continent, only 8% of cyber intelligence analysts have advanced skills in machine-learning-based detection, adversarial AI and cryptocurrency tracing.
  • A serious blind spot in regard to sharing: there is a fundamental failure of real-time data sharing between banking institutions, telecommunication companies and state law enforcement This lack of information sharing results in a huge blind spot, which is taken advantage of by synthetic identity syndicates, as they are able to quickly move stolen funds across various jurisdictions before the authorities can act.

Considering a blueprint for action: it is made obvious by INTERPOL’s report that the capability gaps and related problems, cannot be overcome merely by buying softwares and tech-tools; instead, a coordinated national initiative involving the public, private and civil sectors, is high needed. Since South Africa is currently the country in the world with the third-highest number of cybercrime victims, it should take the lead in the continent by copying proven global cyber programmes and set up an independent national organisation for cybersecurity and intelligence.

At the moment, four only African countries have a dedicated cybersecurity and intelligence organisation. As concerning other African countries, the responsibility is left to their existing parastatals, unlike the pattern of the United States (with CISA and USCYBERCOM) and Australia (which set up its combined offensive and defensive task forces such as “Hack the Hackers”), the other countries in Africa should establish their own well-funded and fully capable National Cybersecurity and Intelligence Organisation.

The key requirement should be that the given agency would be entirely made-up of the nation’s most capable cyber experts and must be entirely free from political appointments and interference. It must also be responsible for the cybersecurity of government departments, state-owned enterprises and critical infrastructure like power grids, water systems, etc., as well as taking active steps to identify threat-actors, so that genuine legal consequences can be imposed for cybercrime.

Launch a public awareness campaign on national cybersecurity: the government should carry out continuous and extensive public enlightenment, since the human element is still the weakest link in the cyber defence chain. For instance, In 2022 the Cybersecurity Agency of Singapore launched the very successful ‘Better Cyber Safe Than Sorry‘ campaign, working with e-commerce sites and employing TV advertisements, posters and multilingual ‘Cyber Safe Seniors‘ enlightenment programmes, in order to train more than 50,000 older citizens to recognise scams.

Draw up a national programme to promote and develop cyber talent: cyberspace is a field of power, and most African countries do not have the specialised talent pipeline needed to defend it.

Emulate Israel’s Talpiot and Unit 8200: Israel manages to have 33% of the world’s cybersecurity unicorns, because it identifies promising high school students and places them in special accelerated programmes, which enable the students to attain university-level expertise before they graduate, thereby feeding directly into its national cyber intelligence command.

Make use of reformed talent: African countries should also support promising school students, provide public-private internship opportunities, proffer practical strategies for rehabilitation misdirected tech-talents; and make use of reformed cyber talent for the purpose of national defence, just like what happened in the past, with the student from Bishops High School who hacked ABSA in 2003, and was then incorporated into the CSIR’s Cybersecurity Research Lab.

Considering a mandate for anonymised real-time data consortiums, in order to eliminate the blind spot associated with structural sharing, African governments should establish and put into action, a secure framework for the exchange of risk signals in real time, such as:

  1. Financial institutions and telecom providers should set up a shared-risk data network, by applying one-way cryptographic hashing to transform sensitive customer identifiers like national ID numbers, BVNs, mobile device fingerprints, etc., into unique and anonymous tokens, so that they can share fraud alerts in real time. This will enable the participating banks to immediately identify, duplicate device patterns or anomalies involving a high rate of transactions without having to expose the actual personal data of customers, thus ensuring full compliance with personal data protection regulations.

To update and unify legal frameworks, the legal systems of the Department of Justice and the African Union Commission should be modernised in order to get rid of the definitional gaps, which enable cybercriminals to avoid being prosecuted.

  1. South Africa and Nigeria should approve the Malabo Convention and put into practice their commitment to the UN Cybercrime Convention.
  2. Legislators should draw up specific protocols for AI that clearly define and make it illegal to fabricate synthetic identities, carry out biometric presentation/injection attacks; clone voices, videos and the of use machine learning tools to automatically run extortion schemes [365].
  3. Set up a 24-hour mutual assistance network of cross-border digital evidence-sharing networking, which includes clear and binding time limits, so that investigators will be able to swiftly trace and recover the stolen funds, as they move through various African jurisdictions [366].

The $484 million loss figure mentioned by INTERPOL, should be taken seriously. Except there is immediate fundamental reform and effective governance, the extent and pace at which AI is being used for exploitation will keep surpassing government social defence structures, and will endanger individual bank accounts, the overall stability of our national infrastructure and state security.

Proactive socio-defence agreement by every country on the field of international law, with nationwide coordination led by cybersecurity experts, are no longer optional policies, but basic necessary requirements, if a secure digital future is to be achieved in this AI era.

Picture Credit: Africa Check | Jub Jub

Leave a Reply

Your email address will not be published. Required fields are marked *