NAIROBI, Kenya
Artificial intelligence is helping criminals turn stolen photographs and personal data into synthetic identities capable of defeating biometric checks, part of a broader expansion of cybercrime across Africa that Interpol says is increasingly outpacing national and institutional responses.
A single photograph taken from a social media profile can be used to create a photorealistic synthetic identity, pairing a fabricated face with a victim’s stolen name and ID number to open a bank account, secure a mobile loan or register a SIM card under a false name, according to Interpol’s African Cyberthreat Assessment Report 2026.
The technique has defeated biometric verification systems in Kenya and Tanzania, the report said. East Africa has also emerged as a hub for mobile money fraud and infrastructure-targeted ransomware.
The International Criminal Police Organization, commonly known as Interpol, facilitates international police cooperation among its member countries.
Interpol crime bureau chiefs are meeting in Nairobi this week to coordinate a regional response.
“No country can address these threats in isolation, and no single institution can match the agility of criminal networks operating across borders,” Neal Jetton, Interpol’s director of cybercrime, wrote in the report’s foreword.
Criminals have moved beyond simple credential theft, the report says. They are combining stolen personal information with AI-generated elements, including fabricated employment histories and synthetic faces, to create digital identities that do not fully belong to real people.
A Continent Industrializing Crime
The 40-page report, dated June 2026, draws on survey responses from 36 of Interpol’s 49 African member countries, representing a 73% response rate. The findings were cross-referenced with telemetry from private-sector partners including Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI.
AI now plays a role in 55% of reported cybercrimes across the continent, according to the report, which describes cybercriminality as evolving from isolated incidents into an industrialized, borderless ecosystem.
Reported cybercrime losses across Africa more than doubled to $484 million in 2025 from $192 million a year earlier, while identified victims rose to 87,000 from 35,000. The report said the figures likely undercount the scale of the problem because of inconsistent reporting among countries.
Aggregated estimates cited in the report put Africa’s direct economic damage from cybercrime at about $5 billion in 2025, compared with total regional cybersecurity spending of $15.3 billion.
The threat varies by region. East Africa has become a hub for mobile money fraud and infrastructure-targeted ransomware, while Central and West Africa have seen a proliferation of business email compromise and romance scams, often using French-language phishing lures.
Southern Africa, anchored by South Africa’s dense data center and subsea cable infrastructure, recorded 92% of ransomware detections on the continent and drew the highest concentration of global threat actors seeking maximum disruption, according to the report.
Kenya’s exposure
Kenya ranks near the top of many of the report’s regional indicators, though several of the threats extend across East Africa.
SIM swap fraud in Kenya surged 327% in 2025, with more than 123,000 fraudulent SIMs issued and an estimated $3.8 million drained from mobile wallets. Tanzania and Rwanda are seeing similar patterns as telecom providers across the region struggle to implement real-time biometric verification, the report said.
Kenya recorded more than 46,786 distributed denial-of-service attacks against telecom operators in the first half of 2025 and was named in a separate industry report’s top phishing-detection ranking in September.
The Communications Authority of Kenya logged hundreds of millions of intrusion attempts against government and information and communications technology infrastructure between July and September 2025, primarily through brute-force and system-exploitation methods.
The Rest of East Africa
Uganda Electricity Transmission Company Limited experienced a suspected ransomware incident in August 2025 that compromised monitoring systems tied to the national power grid. Service was restored through backup protocols, but Interpol cited the incident as a case study in the vulnerability of essential utilities to cyber disruption.
In Tanzania, government-linked social media accounts were compromised during the pre-election period, fueling coordinated disinformation campaigns and attempts to disrupt civic engagement online.
Ethiopia ranked fifth in Africa in vulnerability detections, while Seychelles experienced a targeted breach of its central bank’s customer database, according to the report.
Coordinating a Response
The findings come as an Interpol Policing Capabilities Mentorship Programme is underway in Nairobi for new heads of National Central Bureaus and senior staff from across East Africa.
Directorate of Criminal Investigations Director Mohamed I. Amin, speaking through Deputy Director John Onyango, called for closer regional cooperation on cross-border crimes including cybercrime, trafficking and money laundering. The measures include faster intelligence sharing, joint investigations and wider use of Interpol databases covering wanted people, stolen travel documents and biometric records.
Four coordinated Interpol operations under the Africa Joint Operation against Cybercrime accounted for the bulk of the enforcement results cited for 2025.
Operation Serengeti 2.0 dismantled more than 1,200 malicious servers and seized 1,800 devices across Angola, South Africa and Uganda. Authorities arrested 120 people and disrupted networks tied to $300 million in losses.
Operation Contender 3.0 targeted romance scams and digital sextortion across 14 countries, resulting in 260 arrests and about $2.8 million in recovered proceeds.
Operation Sentinel spanned 19 countries and resulted in 574 arrests, about $3 million recovered and the decryption of six ransomware variants. The report described it as the largest coordinated cybercrime crackdown in African history.
Operation Red Card 2.0 was conducted across 16 countries between December 2025 and January 2026. It resulted in 651 arrests, $4.3 million recovered and the takedown of 1,442 malicious IP addresses and domains linked to $45 million in losses affecting 1,247 victims.
Together, the four operations resulted in more than 1,500 arrests across Africa in less than a year.























