South Africa has emerged as the epicentre of cybercrime in Africa, with the country accounting for 92% of all ransomware detections on the continent and hosting 43,6% of exploitable vulnerabilities, according to a new report released by Interpol.
The African Cyberthreat Assessment Report 2026, released this week, paints a concerning picture of South Africa’s position in the global cyber threat landscape, with the country’s ultra-high connectivity and advanced digital infrastructure making it a magnet for international threat actors seeking maximum disruption.
The report reveals that artificial intelligence is now linked to 55% of reported cybercrimes across Africa, with cybercriminals using AI to automate attacks, making them faster, more scalable, and increasingly difficult to detect.
Cybercrime capital
South Africa’s dominance in Africa’s cybercrime statistics extends beyond ransomware. The country accounts for 70% of business email compromise detections on the continent, with criminal syndicates based in South Africa targeting global enterprises in Europe and North America.
The report also found that South Africa recorded approximately 40% of all African phishing detections and experienced 213 523 distributed denial-of-service attacks.
“Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion,” said Neal Jetton, director of Interpol’s Cybercrime unit.
The financial toll of cybercrime across Africa has more than doubled since 2024, surging from R3 billion to almost R8 billion, driven primarily by AI-facilitated scams, credential harvesting and automated social engineering campaigns.
AI-enabled threats
The report highlights how cybercriminals are leveraging AI to create synthetic identities by combining real personal data with fabricated elements. These AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names.
Digital sextortion and online harassment, often facilitated by AI-generated deepfakes and synthetic media, remained pervasive across the continent, with 600 000 sextortion detections recorded by TrendAI, one of several partners working with Interpol.
Business email compromise schemes have also become more sophisticated, with AI used to generate highly convincing email correspondence that mimics executive tone and language.
The report notes that 72% of surveyed countries reported the presence of scam centres, with the highest concentration in southern and west Africa.
Blind spots in the system
A key vulnerability identified in the report is the absence of real-time, inter-agency data sharing between banks, telecommunications companies and law enforcement, creating dangerous blind spots that criminals are exploiting.
Despite South Africa having a relatively mature regulatory framework, including the Cybercrimes Act, and higher cybersecurity spending than regional peers, persistent gaps in cross-border coordination and real-time threat intelligence sharing remain.
The report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialised, borderless ecosystem.
In 2025, four high-impact cybercrime operations coordinated by Interpol, including Operation Serengeti 2.0 and Operation Contender 3.0, collectively led to more than 1 500 arrests, the seizure of hundreds of devices and the recovery of over R1,6 billion.
The report calls for standardised digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal public-private partnerships to support effective prevention, detection and response.
ALSO READ: South Africa becomes Africa’s top cyber target as AI-driven attacks surge




