• INTERPOL states that South Africa’s advanced digital infrastructure attracts organised cybercriminal networks.
  • The country accounted for 92% of ransomware detections recorded across Africa in 2025 and 70% of business email compromise detections.
  • The report calls for stronger regional cooperation, improved cyber resilience, and greater investment in digital security.

According to the INTERPOL African Cyberthreat Assessment Report 2026, South Africa’s sophisticated digital infrastructure makes it appealing to organised cybercriminal networks. These networks increasingly use artificial intelligence to automate attacks, steal sensitive information, and disrupt vital services.

The assessment includes intelligence from law enforcement, cybersecurity units, and judicial authorities in 36 African member countries, with support from private-sector cybersecurity partners. It warns that cybercrime has become highly organised and cross-border, posing threats to economies, public confidence, and critical infrastructure across the continent.

South Africa faces many ransomware attacks

Southern Africa is described as the continent’s most digitally advanced region. However, INTERPOL notes it is also the most heavily targeted by cybercriminals.

The report indicates that South Africa accounted for 92% of all ransomware detections in Africa in 2025. These attacks impacted critical infrastructure, including the South African Weather Service and South African Airways. Neighbouring Namibia also saw significant attacks on its telecommunications infrastructure.

During the reporting period, South Africa recorded over 213,000 distributed denial-of-service (DDoS) attacks and almost 40% of phishing detections in Africa.

INTERPOL attributes the country’s vulnerability to its extensive digital connectivity, including subsea cable landings and dense data centre networks. This connectivity makes it an appealing target for global cybercriminal groups seeking to maximise disruption.

Critical services are increasingly at risk

The report emphasises that ransomware now goes beyond financial extortion. It is a tool that can disrupt essential public services and critical infrastructure.

Healthcare facilities, government departments, financial institutions, communication networks, energy providers, transport systems, education, manufacturing, and water infrastructure are among the sectors increasingly at risk of organised cybercriminal attacks.

INTERPOL asserts that these attacks show that cybercrime has evolved into a broader economic and national security challenge, rather than just an information technology issue.

Artificial intelligence is changing criminal tactics

The report identifies artificial intelligence as a major factor behind the growing complexity of cybercrime. According to INTERPOL, criminals are leveraging AI to automate phishing campaigns, create convincing deepfakes, generate fake identities for fraud, launch large-scale social engineering attacks, and bypass traditional cybersecurity systems. Cybercrime-as-a-service platforms also make sophisticated attack tools easy to access for criminals with limited technical skills.

INTERPOL Director for Cybercrime Neal Jetton says, “Cybercrime now poses a growing and systemic threat to the economic security, public confidence, and institutional resilience of African countries.”

He notes that the organisation is seeing “a defining shift,” as cybercrime changes “from isolated incidents into an industrialised, borderless ecosystem.”

South Africa also leads in business email compromise

Beyond ransomware, the report highlights business email compromise (BEC) as one of Africa’s most financially damaging forms of cybercrime.

INTERPOL finds that 70% of BEC detections came from South Africa. Criminals increasingly use AI-generated emails to impersonate senior executives and trick finance departments into redirecting payments to fraudulent accounts. A further 29% of detections came from Nigeria.

The report warns that these attacks exploit human trust rather than technical weaknesses. This makes them harder for organisations to detect.

The real cost may be much higher

INTERPOL believes that the scale of cybercrime across Africa is likely much larger than what official numbers suggest.

According to the report, 89% of participating countries indicated that cybercrime remains significantly underreported. This underreporting is due to poor reporting mechanisms, limited forensic capabilities, concerns over reputational damage, and uncertainty regarding legal reporting requirements.

Reported cybercrime losses rose from US$192 million in 2024 to US$484 million in 2025. Meanwhile, the number of identified victims grew from 35,000 to 87,000. The report estimates that cybercrime caused at least US$5 billion in direct economic losses across Africa in 2025.

Stronger cooperation is needed to fight organised cybercrime

INTERPOL emphasises that no country can fight cybercrime on its own because criminal networks increasingly operate across borders.

Jetton states, “No country can address these threats in isolation, and no single institution can match the agility of criminal networks operating across borders.”

He adds that recent operations have shown that “when countries work together, cybercriminal infrastructure can be identified, disrupted, and dismantled.”

The report concludes that African countries should improve cybercrime legislation, enhance digital forensic capabilities, invest in specialised training, expand intelligence sharing, and strengthen cooperation between governments, law enforcement, and the private sector.

It also urges countries to keep pace with emerging technologies, especially artificial intelligence, to better defend against rapidly evolving cyber threats.

Conviction.co.za

Get your news on the go. Click here to follow the Conviction WhatsApp channel.

Share.

Multiple award-winner with passion for news and training young journalists. Founder and editor of Conviction.co.za

Leave A Reply Cancel Reply

Prove your humanity: 0   +   1   =  

Exit mobile version