NewsMacro1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks

1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks

Author: TechNext24·

Key Takeaways

  • •African cyberattack losses more than doubled year-over-year, with reported losses rising from $192 million in 2024 to $484 million in 2025 and INTERPOL estimating true direct economic damage at approximately $5 billion.
  • •Cybercriminals have shifted from financial theft to targeting critical infrastructure, with ransomware attacks disrupting Uganda's national power grid, Nigeria's customs and port operations, and South Africa's meteorological data systems.
  • •INTERPOL and member nations conducted four major coordinated operations in 2025 representing the largest cybercrime crackdown in African history, resulting in over 1,600 arrests and the recovery of approximately $13 million in illicit proceeds.
  • •Underreporting remains pervasive across the continent, with 89% of surveyed countries identifying it as a challenge and only four nations mandating 72-hour breach disclosure.
  • •Kenya experienced a 327% surge in SIM swap fraud in 2025, with over 123,000 fraudulent SIM cards issued and an estimated $3.8 million drained from mobile wallets, exploiting institutional gaps in real-time biometric verification and fragmented inter-agency reporting.
1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks

In August 2025, operators at Uganda’s Electricity Transmission Company Limited watched their network monitoring screens freeze. A ransomware variant had compromised the systems governing the national power grid. Service was restored only through backup protocols, but the incident confirmed what law enforcement across the continent had already suspected: African cyberattacks had moved beyond theft into sabotage.

The shift is documented in detail in INTERPOL’s African Cyberthreat Assessment Report 2026, compiled from 36 member countries and private sector telemetry. The picture is not one of isolated hackers, but of an industrialised ecosystem targeting the physical infrastructure that economies depend on.

Seven months before Uganda’s grid flickered, the South African Weather Service suffered a suspected ransomware attack that corrupted critical meteorological data systems, and the disruption rippled outward into aviation routing and maritime navigation services. In Nigeria, the Customs Service was hit in August 2025 by a ransomware variant that paralysed cargo clearance at major ports, generating an estimated $18 million in storage fees and import delays. In Namibia, the national telecommunications provider lost 500,000 personal and financial records after an unsecured administrative portal was exposed to the public internet, while a separate attack by the Akira group targeted Paratus Telecom and disrupted core network services.

The financial toll is stark. Reported cyberattack losses across Africa more than doubled between 2024 and 2025, rising from $192 million to $484 million, while the documented victim count increased from 35,000 to 87,000. INTERPOL estimates the true direct economic damage at roughly $5 billion in 2025, against a continental cybersecurity expenditure of $15.3 billion in the same year. Defences are growing, but the attacks are growing faster.

What distinguishes the current wave is its concentration on critical infrastructure. FortiGuard Labs telemetry shows that threat actors are using automated reconnaissance tools capable of scanning tens of thousands of systems per second, targeting outdated routers, vulnerable VPNs, and misconfigured cloud services. The Shadowserver Foundation identified more than 6,000 exploitable vulnerabilities across Africa in 2025, concentrated in South Africa, Kenya, and Nigeria. The Sliver command-and-control framework, an open-source tool weaponised by criminal actors, was used to deploy novel ransomware strains. Cameroon alone recorded 40.5 million botnet detections in 2025, the second highest in Africa, while Angola showed similarly high levels of compromised device activity.

Yet the most visible failures may be the least reported. According to the INTERPOL survey, 89% of member countries cited underreporting as a pervasive challenge. Only Nigeria, Kenya, South Africa, and Mauritius mandate breach disclosure within 72 hours. Many agencies lack formal incident reporting mechanisms, and victims often fear reputational damage. The result is a landscape in which the known attacks are almost certainly a fraction of the real total.

The institutional response has been forceful and unprecedented in scale. In 2025, INTERPOL and member countries conducted a series of coordinated multinational operations that represent the largest cybercrime crackdown in African history.

Operation Serengeti 2.0, conducted early in the year, targeted illegal cryptocurrency mining operations, scam centres, and ransomware infrastructure across Angola, South Africa, and Uganda. It dismantled more than 1,200 malicious servers, seized 1,800 devices, and resulted in 120 arrests, disrupting networks responsible for $300 million in losses.

Operation Contender 3.0, spanning July and August, focused on romance scams and digital sextortion across 14 African countries. It yielded 260 arrests, the seizure of more than 1,200 devices, the identification of 1,500 victims, and the dismantling of 81 online crime networks, with an estimated $2.8 million in illicit proceeds recovered.

Operation Sentinel, running from October to November, was the largest coordinated operation to date, spanning 19 nations and targeting BEC, digital extortion, and ransomware. It produced 574 arrests, the recovery of approximately $3 million, the takedown of more than 6,000 malicious links, and the decryption of 30 terabytes of ransomware-encrypted data in Ghana alone.

Operation Red Card 2.0, from December 2025 to January 2026, targeted high-yield investment fraud, mobile money scams, and fake loan applications across 16 countries. It resulted in 651 arrests, the recovery of $4.3 million, the seizure of 2,341 devices, and the takedown of 1,442 malicious IPs and domains, uncovering scams responsible for $45 million in losses affecting 1,247 victims.

But the report makes clear that operations alone cannot close the gap. The survey found that 72% of African countries reported the presence of scam centres operating within their borders, concentrated heavily in Southern and West Africa. INTERPOL explicitly links these centres to human trafficking and transnational organised crime, describing facilities where victims are held against their will and forced to conduct scams. In many cases, the romance scam and the trafficking case are increasingly the same.

The systemic vulnerabilities extend to the foundations of digital finance. In Kenya, SIM swap fraud surged 327% in 2025, with more than 123,000 fraudulent SIM cards issued and an estimated $3.8 million drained from mobile wallets. Tanzania and Rwanda reported similar patterns. The root cause was institutional: telecom employees were working without real-time biometric verification, and reporting systems were so fragmented that victims had to navigate between banks, telecoms, and police who do not share data with one another in real time.

Law enforcement capacity remains unevenly distributed. Ninety-four percent of agencies reported insufficient digital forensics tools, 78% cited inadequate budgets, and only 17% of countries maintain cybercrime units with more than 100 personnel. Seventy-two percent reported slow data exchange between agencies, while 89% identified cross-border cooperation as the single largest barrier to successful investigations.

AI readiness is also alarmingly low. While 55% of cybercrime cases in 2025 involved AI in some capacity, only 8% of intelligence analysts across the continent have advanced expertise in identifying AI-generated content, and frontline officers generally lack training to distinguish authentic media from synthetic voice clones or deepfaked video. The report notes that while 33% of agencies have begun using AI for threat detection, the majority still rely on manual processes.

In 2025, 17 countries enacted or amended cybercrime laws. Kenya advanced legislation specifically targeting SIM swaps, Zambia enforced its Cyber Crimes Act, Angola established a National Cybersecurity Centre, and Senegal allocated $24 million to digital sovereignty initiatives. But implementation remains the critical next step, and legal harmonisation across borders is still incomplete.

When Uganda’s power grid came back online in August 2025, the attackers had not been caught, the vulnerabilities they exploited had not been patched, and the legal frameworks required to pursue them across jurisdictions remained tangled in administrative delays and divergent data protection regulations. The grid recovered because the utility had backups, though the underlying fragility remained unchanged, and the report suggests that more systems are one unsecured portal, one fraudulent SIM, or one ransomware variant away from going dark.

For most Africans, the report’s $5 billion headline is abstract. The more immediate reality is the mobile money notification that never arrives, the SIM card swapped without consent, or the WhatsApp voice note that sounds exactly like someone you trust. The INTERPOL data suggests that the continent’s fastest-growing fraud vectors do not require victims to be wealthy or careless, only to be connected. With more than 1.1 billion mobile subscriptions and $1.1 trillion in digital transactions recorded in 2025, the attack surface is now the phone in your pocket.

The survey found that mobile money fraud was reported by 97% of the countries surveyed, and Kenya’s 327% surge in SIM swap fraud shows how quickly a single compromised telecom employee can drain a shopkeeper’s daily takings before lunch. The report notes that only four countries mandate breach disclosure within 72 hours, which means the average user often has no warning that their data is already circulating on dark web forums, where S2W data showed a 62% year-over-year increase in African-origin stolen content. You do not need to click a phishing link to become a victim; you only need to have a phone number and a national ID.

Then there is the AI factor. Deepfake investment scams, synthetic identity fraud, and automated sextortion campaigns are no longer targeting corporations and high-net-worth individuals. They are targeting anyone with a social media profile and a mobile wallet. The report’s most sobering finding for ordinary users may be institutional rather than technical: banks, telecoms, and police do not share fraud data in real time, and 89% of surveyed countries say cross-border cooperation is their biggest investigative barrier. For the average African, that translates to a simple, frustrating truth. If the money leaves your account on a Friday afternoon, the systems designed to protect you may not talk to each other until Monday, and by then the trail is cold.