INTERPOL report reveals AI drives 55% of cybercrime in Africa with losses reaching $484M

INTERPOL report finds AI behind 55 per cent of African cybercrime

INTERPOL released its African Cyberthreat Assessment Report 2026 on 3 August 2026, finding that artificial intelligence now enables 55 per cent of all reported cybercrime across African member nations. The 40 page assessment draws on survey responses from 36 countries and documents a shift from manual, human paced attacks to an industrialised, AI automated cybercrime economy operating across borderless digital networks. Total financial losses linked to cybercrime in the region have more than doubled since 2024, reaching USD 484 million.

The report matters well beyond Africa. Multinational businesses, professional services firms and consultancies with supply chains, transaction counterparties or client relationships touching African markets are now exposed to attack methods that operate at machine speed rather than human speed. That includes environmental and property sector firms managing cross border due diligence, settlement transfers and regulator correspondence, where a single compromised email thread or spoofed instruction can result in significant financial loss.

For risk officers, transaction lawyers, in house counsel and consultants advising on international dealings, the findings confirm that defensive frameworks built around periodic review and human verification are no longer adequate against adversaries using autonomous AI agents and synthetic media at scale.

Deepfake fraud, autonomous AI agents and scam centres: key findings

INTERPOL’s assessment found that AI now underpins the majority of cybercrime activity reported by law enforcement agencies across the 36 surveyed countries, with autonomous AI agents conducting reconnaissance, harvesting credentials, generating targeted phishing content and executing ransomware campaigns with minimal human oversight. This is described in the report as a move from opportunistic, one off attacks toward an industrialised criminal ecosystem.

Deepfake enabled fraud has escalated sharply. Security partner TrendAI recorded more than 600,000 deepfake assisted sextortion detections across surveyed networks during the 2025 to 2026 period. Business email compromise schemes increasingly use real time voice and video synthesis to defeat standard authorisation checks, allowing attackers to impersonate executives, clients or counterparties convincingly enough to redirect payments or extract sensitive information.

Regional infrastructure exposure is significant and unevenly distributed. Active scam centres were identified in 72 per cent of surveyed countries. East Africa reported specialised mobile money fraud and infrastructure targeted ransomware, while Southern Africa experienced high disruption linked to its dense, hyper connected digital networks. These figures indicate that criminal groups are adapting tactics to the specific financial and telecommunications infrastructure of each sub region rather than applying a uniform attack model.

The report also identifies a defensive readiness gap. While criminal groups rely on low cost synthetic media tools and automated scripting to scale attacks cheaply, regional law enforcement agencies report alarmingly low levels of AI readiness and technical tooling to detect, attribute or disrupt these campaigns. INTERPOL frames this gap as the central operational challenge for the region going forward.

microsoft.com
Image source: microsoft.com

What AI enabled cybercrime means for Australian businesses

Australia has no equivalent AI driven cybercrime dataset of this scale, but the trends described in the INTERPOL report are directly relevant to Australian businesses and professional services firms operating internationally or handling cross border transactions. The Australian Cyber Security Centre’s Essential Eight mitigation strategies, and mandatory notification obligations under the Privacy Act 1988, remain the baseline compliance frameworks, but neither was designed with autonomous AI agents or convincing real time deepfake impersonation in mind.

Australian firms that engage African counterparties, suppliers, joint venture partners or offshore service providers for professional or technical services should treat this report as a warning that business email compromise and deepfake assisted impersonation are no longer edge cases. ASIC has flagged cyber and AI enabled fraud risk as a governance priority for regulated entities, and AUSTRAC continues to monitor business email compromise patterns affecting fund transfers involving Australian financial institutions. The INTERPOL findings reinforce that these risks are growing in scale and sophistication rather than plateauing.

For professional services firms more broadly, including those managing property transactions, regulatory correspondence and technical reporting workflows, the report is a useful reference point when briefing clients on why verification protocols for financial instructions and official communications need to move beyond a single email confirmation.

INTERPOL report reveals AI drives 55% of cybercrime in Africa with losses reaching $484M
Image source: AI-generated supporting image

How firms can protect payments and correspondence from AI driven fraud

Organisations should assume that any unverified request to change payment details, urgently transfer funds or respond to a regulator style communication could be the product of an automated or deepfake assisted attack rather than genuine correspondence. Out of band verification, meaning a phone call to a known number or an in person confirmation, should be standard practice for any material change to financial instructions, not an optional extra reserved for high value transactions.

Risk and compliance teams should update onboarding and transaction protocols to require secondary verification for new banking details, and should train staff to recognise that voice and video can now be synthesised convincingly within minutes. This is particularly relevant for teams managing settlement processes, supplier payments or any workflow where a compromised instruction could result in irreversible fund transfer.

Firms should also review how they authenticate incoming official correspondence, including regulator notices, government agency requests and approval related communications. Sender addresses, letterheads and document formatting can all be convincingly replicated, so any correspondence requesting payment, sensitive data or urgent action should be confirmed through an independently sourced contact channel before staff respond. Building these verification steps into standard workflows now is considerably cheaper than recovering from a machine speed fraud after the fact.

References and related sources

How iEnvi can help

iEnvi integrates technology and data-driven approaches into environmental consulting. We monitor AI and technology developments that affect how environmental professionals deliver services to clients.


This is an iEnvi Machete news summary. Prepared by iEnvi to summarise the source article for environmental professionals tracking AI, data, and technology developments that affect consulting and project delivery.

Published: 03 Aug 2026

Need advice on this topic? Speak to an iEnvi expert at info@ienvi.com.au or 1300 043 684, or contact us online.

Need advice on this issue? iEnvi provides practical, senior-led environmental consulting across contaminated land, remediation, ecology and environmental risk.

Environmental due diligence Talk to iEnvi