Introduction
Since 2021, INTERPOL has published successive assessments of Africa’s evolving cyberthreat landscape. Read together, they reveal something more interesting than a changing list of cyber threats: the same cyber-enabled financial crimes keep returning, but the way criminals carry them out is changing.
Business email compromise, online scams, identity theft, mobile-money fraud, ransomware, digital extortion and sextortion all appear across the assessments. What has changed is the technology and infrastructure surrounding them, making these crimes faster, cheaper, more convincing and easier to scale.
And this is not just a problem for banks, governments or cybersecurity teams.
The victims are often ordinary people: someone who believes they have found love online, a small-business owner suddenly locked out of their systems, or an employee who approves an invoice because the request appears to come from someone they trust. The technology may enable the fraud. But very often, a human decision is what makes the payment happen.
The Five-Assessments Story at a Glance
The core typologies remain remarkably persistent. What changed, edition after edition, was how convincingly, quickly and cheaply they could be executed.

Source: INTERPOL African Cyberthreat Assessment Reports, 2021, 2023, 2024, 2025 and 2026.
The Five Core Typologies
Business Email Compromise
From Fraudulent Emails to Identity Manipulation BEC is one of the clearest examples of cyber-enabled financial crime. The attack may involve phishing, a compromised account, a fake domain or an impersonated executive. But the technology is only part of the story. The real objective is to influence someone into making a financial decision.
INTERPOL’s 2024 assessment show BEC becoming increasingly sophisticated; by 2025 it was flagging AI-driven BEC and deepfake executive impersonation. And that changes where organisations need to look for the point of failure. It may not be the compromised account. It may be the moment someone decides to approve the payment. That makes payment verification, behavioural signals and escalation of unusual instructions just as important as technical security.
Online Scams The Broadest and Most Adaptable Typology
Online scams cover a wide range of activity — from phishing and romance scams to investment and e-commerce fraud. What makes them particularly difficult is that the victim may never realise they are being defrauded until the money is gone. Criminals use social media, messaging platforms and increasingly AI to find people, build trust and keep conversations going. The goal is not necessarily to break into an account. It is to persuade the person who owns the account to move the money themselves.
That creates a difficult challenge for financial institutions. The customer may be genuine. The login may be genuine. The device may be genuine. And the transaction can still be fraudulent.
Ransomware and Digital Extortion: Turning Access Into Leverage
Ransomware sits at the intersection of cyber intrusion and financial crime. Criminals gain access to systems or data and then use that access as leverage for payment. Increasingly, the impact extends beyond individual businesses to critical infrastructure and essential services.
The regional picture also matters. INTERPOL’s assessments point to different patterns across Africa: Southern Africa’s high connectivity increases exposure to sophisticated attacks, infrastructure-targeted ransomware is a particular concern in parts of East Africa, and elsewhere ransomware increasingly intersects with broader organised criminal ecosystems. The important point for financial-crime teams is simple: The ransom payment is only the visible end of a much longer criminal process.
Mobile-Money and Account-Takeover Fraud
The Other Side of Digital Growth. Africa’s rapid adoption of mobile financial services has transformed how people access and move money. It has also created another opportunity for criminals. Mobile-wallet fraud, SIM swaps, telecom impersonation and account takeover allow criminals to exploit trusted financial channels without necessarily needing sophisticated malware.
INTERPOL identifies mobile-money fraud as a particular concern in East Africa. Kenya provides a striking example: SIM-swap fraud reportedly surged 327% in 2025 , with more than 123,000 fraudulent SIMs issued and around $3.8 million drained from mobile wallets. The broader lesson is even more important:The customer account is not the only unit of risk. The phone number attached to it is one too.
Digital Sextortion
When Personal Information Becomes Financial Leverage. Digital sextortion shows how quickly personal information can become a financial weapon. Criminals may obtain genuine intimate material through deception or coercion or increasingly use AI-generated content to create something convincing enough to threaten a victim. The demand is simple: pay, or face exposure.
INTERPOL’s 2025 assessment found that 60% of surveyed African member countries reported an increase in digital sextortion. By 2026, AI-generated content and deepfakes were becoming an increasingly important part of the threat. Identity crime creates another route to financial loss, with stolen personal information increasingly combined with fabricated details to create synthetic identities. The result is a growing overlap between cybercrime, fraud and traditional financial-crime controls.
The Enabling Layer: From Crimeware-as-a-Service to AI

The biggest change across the assessments may not be a new crime type at all. It is the industrialisation of the capability behind existing crimes.
Crimeware-as-a-Service
means criminals no longer need to build every tool themselves. They can buy phishing kits, malware, infrastructure and other services from specialised providers. The person running the scam may never have written a line of code. They may simply have rented the toolkit.
AI takes this one step further.
INTERPOL’s 2026 assessment linked AI to 55% of reported cybercrime across Africa. AI does not necessarily create a new type of financial crime. Instead, it changes the economics of existing ones, helping criminals create more convincing messages, impersonate trusted people, personalise attacks and reach more victims at greater speed.
AI is becoming a force multiplier for familiar crimes.
What Financial Crime Professionals Should Take From This
1. Look beyond the transaction
: The payment is often the end of the story, not the beginning. Look at what happened before it: the communication, device, beneficiary, customer behaviour and events that led to the payment.
2. Follow the money and the criminal supply chain
: The person receiving the money may be only one part of a much larger network. Understand who provides the tools, who recruits victims, who controls the accounts and who moves the money afterwards.
3. Treat legitimate customers as potential victims
: Not every fraudulent payment comes from a compromised account. A genuine customer can be manipulated into making a legitimate-looking transaction. Behavioural changes, new beneficiaries, unusual devices and unexpected payment patterns can therefore be just as important as traditional transaction monitoring.
4. Strengthen controls at the human decision point
>: As AI makes impersonation more convincing, authentication alone becomes a weaker defence.
Sometimes the most effective control is also the simplest: pause the payment. A callback to a known number, confirmation through a second channel or escalation when several warning signs appear can prevent a fraudulent payment before it happens.
5. Use regional intelligence
: Africa is not one risk environment. Mobile-money fraud is particularly prominent in parts of East Africa , while BEC and romance scams feature strongly in Central and West Africa. Controls should reflect those differences rather than treating the continent as a single risk profile.
Where This Is Headed
The next assessment may not introduce a completely new list of crimes. Instead, we are likely to see the same vulnerabilities exploited more efficiently: trust, identity, urgency and human error. Africa’s digital economy will continue to expand. With more than 1.1 billion mobile subscribers recorded in 2025, the potential digital reach is enormous. At the same time, INTERPOL reported cybercrime-related losses rising from around $192 million in 2024 to $484 million in 2025, while 72% of surveyed countries reported the presence of scam centres.
The challenge is therefore not simply to build better cybersecurity. It is to make sure cybersecurity, fraud, AML and financial-crime teams are looking at the same criminal activity from different angles. Because the criminals already are.
Conclusion
The story emerging from five INTERPOL assessments is not that Africa suddenly has a long list of new financial crimes. The core crimes are remarkably familiar. What has changed is the machinery around them.
Technology gives criminals greater reach. Social engineering gives them influence. Criminal ecosystems give them scale. AI gives them speed and convincing impersonation.
And somewhere at the end of that chain, there is often still a person making a decision: clicking a link, trusting a message, changing a beneficiary or approving a payment.
That human decision may be the final point of failure, and the most important point of intervention. The future of financial crime will not be purely cyber or purely financial. Increasingly, it will be both.