Africa's Cybercriminals Outpacing Law Enforcement in AI Adoption, Interpol Report Finds
Key Takeaways
- •AI was implicated in 55% of cybercrime cases observed by African countries surveyed by Interpol in 2025, with deepfake incidents surging sevenfold between the second and fourth quarters of 2024.
- •Only 8% of intelligence analysts possessed advanced AI expertise, and 92% of law enforcement agencies identified a lack of technical knowledge as their primary barrier to deploying AI tools.
- •Africa processed over $1.1 trillion in digital transactions across more than 1.1 billion mobile subscriptions in 2025, making the continent's expanding digital economy a particularly attractive target for cybercriminals.
- •Approximately 72% of African countries surveyed reported the presence of organized scam centres, with Interpol describing them as criminal enterprises maintaining supply chains for recruitment, technology, and money laundering.
- •Nearly 89% of respondents identified cross-border cooperation as the greatest barrier to successful investigations, while 94% of agencies lacked adequate digital forensics tools.

African law enforcement agencies and cybercriminals have comparable access to artificial intelligence, but they are not adopting the technology at the same pace, according to Interpol's African Cyberthreat Assessment Report 2026.
AI was implicated in 55% of cybercrime cases observed by African countries surveyed by Interpol in 2025. Criminals leveraged the technology to craft convincing phishing messages, fabricate identities, and impersonate executives and public figures. Deepfake incidents surged sevenfold between the second and fourth quarters of 2024 alone.
Law enforcement agencies, by contrast, are adopting the same technology at a far slower rate. Only 8% of intelligence analysts surveyed possessed advanced AI expertise, while 92% of agencies identified a lack of technical knowledge as their primary barrier to deploying AI. Most agencies continue to rely on manual processes.
"Criminals are now operating at machine speed," Interpol stated. Law enforcement remains hampered by "legal processes, bureaucratic delays, and a lack of technical capacity."
Lowering the Cost of Sophistication
This growing imbalance is opening a new front in the AI landscape. The technology is reducing the cost and difficulty of common fraud techniques such as phishing and SIM-swaps, allowing them to scale faster than the institutions tasked with stopping them can adapt.
Phishing, identity theft, and financial fraud long predate AI. What has shifted is the level of effort and expertise required to execute these schemes convincingly and at volume.
Interpol noted that generative AI tools, once the exclusive domain of researchers and developers, have become widely accessible and are being "weaponised by criminal actors with minimal technical expertise." AI is now deployed across the entire attack lifecycle — from identifying potential victims and generating phishing content to extortion and evading detection.
The stakes are particularly high for a continent where rapid digitisation has drawn hundreds of millions of people into mobile-phone-based financial systems. Africa hosts the world's largest mobile money market by transaction value and volume, a position it has held for several consecutive years according to GSMA industry data. The continent had more than 1.1 billion mobile subscriptions and processed over $1.1 trillion in digital transactions in 2025, according to data cited by Interpol. Approximately 570 million people use the internet, increasingly accessing banking, healthcare, education, and government services online.
Greater digital activity also generates more valuable data when systems are breached. African-origin material surfacing on dark-web forums rose 62% year on year, encompassing identity documents, banking credentials, SIM PINs, and mobile-money account details — all of which AI can transform into more convincing fraud.
Interpol reported that AI-generated audio and video — deepfakes — have been used to impersonate government officials, corporate executives, and family members. In Uganda, a deepfake of a prominent public figure was deployed to promote a fraudulent investment scheme, resulting in losses exceeding $2 million.
Fraud is also becoming more industrialised. Roughly 72% of African countries surveyed reported the presence of scam centres, concentrated particularly in southern and western Africa.
"These are not random actors; they are organized criminal enterprises," Interpol said. These networks maintain supply chains for recruitment, technology, money laundering, and evasion, and are increasingly turning to AI to produce personalised lures, cloned voices, and fabricated testimonials.
Institutional Constraints on Law Enforcement
Africa's cybersecurity vulnerability is partly technological, but Interpol's findings reveal that it is equally institutional. The challenge for African governments is not merely that criminals possess superior technology, but that criminals can adopt it without needing significant new infrastructure. Most law enforcement agencies cannot.
According to the report, 94% of agencies surveyed said they lacked adequate digital forensics tools. Only 22% of digital forensics units had a working understanding of AI-driven threats, and many cybercrime units operated with fewer than 10 personnel.
Bureaucracy compounds the problem. Nearly three-quarters of respondents reported slow information exchange between agencies, while 89% identified cross-border cooperation as the greatest barrier to successful investigations. The African Union's Convention on Cyber Security and Personal Data Protection, known as the Malabo Convention, entered into force in 2023 after nearly a decade of slow ratification, but implementation and harmonisation across member states remain uneven — a gap that directly impedes the cross-border data sharing and joint investigations the report describes.
Even when banks detect suspicious transactions, Interpol noted, they may lack the authority or technical channels to immediately block an associated SIM swap or freeze an account. Securing court orders can take weeks or months. Telecom companies encounter similar constraints when police request SIM-swap records. Fintech and mobile-money operators have not yet integrated real-time fraud alerts with national law enforcement systems, leaving IP logs, transaction trails, and account information dispersed across institutions.
Cybercrime investigations depend on a chain of entities — police, prosecutors, courts, banks, telecom operators, technology companies, and increasingly, their counterparts in other nations. Criminals face none of these hurdles.
Cybercrime-as-a-Service
The most capable AI models are already available as consumer products or through APIs, while cybercrime-as-a-service markets offer specialised tools to individuals who lack the skills to build them. Interpol said this has "democratised access to advanced attack tools," enabling relatively low-skilled criminals to execute sophisticated operations.
For law enforcement, integrating the same technology is far more complex. Agencies must procure tools, train investigators, and ensure that evidence gathered with AI can hold up in court. Investigations involving banks or telecom companies must comply with regulations governing access to private information. When a suspect, victim, server, or bank account is located in another country, an entirely separate legal framework comes into play.
Cybercriminals, however, face few of the structural obstacles that dominate Africa's AI policy debate. They require no sovereign data laws, national AI strategies, or large talent pools. They need only access to an open-source model, stolen data, and a destination for funds extracted from victims. The asymmetry Interpol describes — offensive actors adopting AI freely while defenders navigate procurement, training, and legal compliance — mirrors a structural challenge flagged by cybersecurity agencies worldwide, but its consequences are more acute in regions where digital infrastructure has expanded faster than the institutional safeguards designed to protect it.