South Africa tops Africa cybercrime rankings as AI powers attacks: Interpol 2026
Synopsis
Key Takeaways
South Africa has become the primary target of cybercriminals across Africa, accounting for the largest share of ransomware, phishing, and business email compromise detections on the continent, according to Interpol's African Cyberthreat Assessment Report 2026. The 40-page report, released on Monday, 4 August 2025 and based on data from 36 African countries, identifies Southern Africa as 'the continent's most digitally advanced and most heavily targeted region.'
Key Detections and Attack Scale
The scale of South Africa's exposure is striking. According to the report, the country accounted for 92 per cent of all ransomware detections in Africa recorded by TrendAI. It also registered 213,523 distributed denial-of-service (DDoS) attacks, including a single incident that peaked at 312 gigabits per second.
South Africa further accounted for nearly 40 per cent of all African phishing detections tracked by cybersecurity firm SOCRadar, and 70 per cent of business email compromise detections in 2025 based on TrendAI data. These figures collectively position the country as the continent's most exposed digital economy.
Financial Losses More Than Double
Financial damage from cybercrime across Africa has surged dramatically. Losses more than doubled between 2024 and 2025, rising from $192 million to $484 million, according to the Interpol report. Online scams remained the most frequently reported category, with criminals leveraging mobile money platforms, social media, and artificial intelligence to reach victims at scale.
The report noted that 72 per cent of surveyed African countries reported the presence of scam centres, with the highest concentrations found in Southern and West Africa.
AI Is Reshaping the Threat Landscape
Interpol's assessment warns that cybercrime across Africa has evolved from isolated incidents into what it describes as 'an industrialized, borderless ecosystem,' driven increasingly by artificial intelligence and automated tools.
Neal Jetton, Director of Interpol's Cybercrime Unit, said in a statement: 'Cybercrime has emerged as one of the most significant criminal threats to the region.' He added: 'AI is automating every stage of a cyberattack, from reconnaissance and phishing to extortion and evasion.'
Jetton also struck a note of cautious optimism: 'However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled.'
Advanced Frameworks, Persistent Vulnerabilities
The report underscores a central paradox: despite having some of the continent's most developed cybersecurity frameworks, Southern African countries remain vulnerable to the speed and scale of AI-enabled attacks. The automation advantage currently lies with attackers, not defenders.
This comes amid growing international pressure on African governments to strengthen cross-border cyber cooperation. Interpol's findings are expected to inform regional policy discussions on digital crime in the months ahead.