Africa lost $484 million to cyber fraud in a single year, according to INTERPOL
Identity fraud in Africa is undergoing a rapid transformation driven by artificial intelligence. This is highlighted in INTERPOL’s African Cyberthreat Assessment Report 2026, which brings together data from 36 member countries and private-sector partners to assess the state of cybercrime across the continent in 2025.
Cybercrime-related losses in Africa rose from $192 million to $484 million between 2024 and 2025. The number of identified victims nearly tripled, from 35,000 to 87,000 people. The report attributes much of this increase to a single factor: artificial intelligence, which was already involved in 55% of cybercrime cases recorded during that period.
This use of AI is not limited to isolated attacks. According to the report, AI has become a mass-production tool for one particular type of fraud: synthetic identities.
These are profiles that combine real personal data with fabricated elements, specifically designed to bypass Know Your Customer (KYC) protocols. They have been used to open bank accounts, apply for mobile microloans, and register SIM cards under false names.
The case of Nigeria
Nigeria’s response illustrates just how difficult it is to keep fraudsters at bay. In 2024, the country linked SIM card registration to its national identification number (the NIN-SIM policy), requiring every user’s identity to be verified before a mobile line could be activated. The measure significantly reduced identity fraud that year.
The scammers’ response was swift. In 2025, fraud hotspots shifted to Cameroon, Mali, and Tanzania, where gaps in KYC enforcement persist, particularly in rural areas and informal financial systems. The pattern repeats itself: wherever one vulnerability is closed, another emerges in a neighboring country.
A risk map that shifts from region to region
INTERPOL’s assessment makes it clear that there is no single profile of fraud across the continent, but rather several distinct ecosystems, each operating according to its own dynamics.
| Region | Dominant Threat | Key Data |
|---|---|---|
| Southern Africa | Ransomware targeting critical infrastructure | South Africa accounts for 92% of detections across the continent |
| West Africa | Business Email Compromise (BEC) | Nigeria and Cape Verde among the hardest hit; a crypto ecosystem with USD 205 billion in transactions |
| East Africa | Mobile money fraud | Kenya: +327% in SIM-swap fraud, with USD 3.8 million in losses |
| Central Africa | Botnets and social engineering | Cameroon is Africa’s second-largest hotspot for botnet detections |
None of these threats operate in isolation. Behind these regional ecosystems lies a link that connects them all and is rarely mentioned: the money mule account.
The report found that 77% of people exposed to fraud in Africa were familiar with the practice of money muling. Only 12% understood its legal consequences or recognized it as a form of criminal complicity.
Most were recruited through job offers presented as legitimate, under titles such as “financial agent” or “remote transaction manager,” without knowing that they were helping move funds from BEC schemes, ransomware attacks, or crypto scams.
And that money does not always stay where it starts. One example is a BEC attempt originating in Senegal that sought to divert $7.9 million from an oil company before authorities managed to freeze the recipient account. The case confirms a pattern that INTERPOL describes in several of its investigations: actors based in Africa, targets in Europe and North America, and infrastructure spread across multiple jurisdictions.
The same pattern appears among other groups identified in this investigation. One, based in South Africa and active since 2017, systematically targets U.S. companies. Another, based in Nigeria and active since 2021, channels illicit funds into international money-laundering networks through crypto exchanges and shell companies.
Why this matters
The report describes a form of fraud that no longer relies on a single type of attack, but rather on a chain: a data breach fuels phishing, phishing fuels the creation of synthetic identities, and those identities eventually become money mule accounts.
Stopping one link in the chain without addressing the others leaves much of the problem untouched.
Against this backdrop, the sector faces several challenges at the same time:
- More robust identity verification, capable of detecting synthetic identities even when they combine real data with spoofed biometric information.
- Cross-border regulatory cooperation, given that much of the fraud exploits legal differences between countries.
- Financial education aimed at potential money mules, to reduce recruitment through fraudulent job offers.
- Data sharing between the banking, telecommunications, and cybersecurity sectors, to break the chain before a data breach turns into an active fraudulent account.
Source: INTERPOL, African Cyberthreat Assessment Report 2026.