55 Percent of Africa’s Cybercrime Now Uses AI. Why Your Money Can Be Stolen and You Can Still Be Blamed

INTERPOL’s latest report on the growing use of artificial intelligence to aid cybercrime across Africa should force governments to confront a problem their financial systems have largely ignored so far.

Development Diaries reports that more than half of reported cybercrime incidents across Africa now involve artificial intelligence, according to INTERPOL’s 2026 African Cyberthreat Assessment Report.

The report found that AI was involved in 55 percent of reported incidents, while financial losses more than doubled since 2024 to an estimated $484 million.

Online scams remain the most common threat, with criminals increasingly using synthetic identities to bypass biometric verification and commit fraud, alongside growing phishing, ransomware and mobile money attacks.

The $484 million is also only the reported loss, as mobile money fraud is routinely under-reported because victims often expect little to come from reporting a relatively small loss, while pursuing a complaint can cost more than the money stolen.

African governments have spent years making biometric identity the key to financial and public services. A fingerprint or face is supposed to provide stronger proof of identity than a password, which is why biometric systems now sit behind bank accounts, SIM registration, mobile money, pensions and social transfers.

But AI is changing that calculation, as a synthetic identity can combine a generated face, fabricated documents and other personal details to pass remote verification.

Once the system accepts that identity, the fraudster can potentially obtain the same financial access granted to a legitimate account holder.

The efficiency of a single national credential therefore comes with a weakness that is easy to overlook because when one identity opens several doors, defeating the identity check can open several doors at once.

No African government has published a continent-wide or national fraud rate showing how often its biometric identity systems are successfully defeated.

The financial liability is another problem to address, as in many African markets, customers who technically authorised a transaction after being deceived can struggle to recover their money.

That approach was easier to defend when scams depended largely on the victim responding carelessly to a suspicious message.

But in today’s AI world, it is increasingly difficult to defend because a person can authorise a payment after receiving a convincing voice clone of a relative, a deepfake of a bank official or a message from an identity that passed the provider’s own verification system.

Women running informal savings groups face a particularly harsh version of this problem, with groups known across Africa as ajo, esusu, susu, chamas and stokvels having moved substantial amounts of collective savings onto mobile money, making financial services easier to access while often concentrating group funds in one treasurer’s wallet.

A successful scam against that wallet can wipe out the contributions of dozens of households at once.

Low-literacy users also face greater exposure to phishing and social engineering, as scam messages, which once gave themselves away through poor spelling, strange wording or awkward translations, now read as fluent messages in local languages and imitate the style of people victims already know with the use of a generative AI tool.

Rural users face another barrier, as reporting fraud often requires a trip to an agent, bank or regulator, making distance another reason a loss may never enter official statistics, while persons with disabilities can face inaccessible warnings and complaint systems designed around sight, hearing or physical mobility.

These gaps sit alongside obligations that African governments have already accepted. The Malabo Convention requires state parties to establish frameworks for cybersecurity, personal data protection and electronic transactions, including consumer protection.

The African Charter also protects the right to property, while national data protection laws impose security obligations on organisations handling personal data.

A provider whose biometric verification is defeated by a synthetic identity should therefore be able to explain what security obligation applied, whether its controls were adequate and who carries the loss when those controls fail.

The institutions already have distinct pieces of the answer, with central banks regulating payment systems and determining liability rules; telecommunications regulators oversee mobile money in several markets; data protection authorities can enforce security obligations on data controllers; national cyber-response agencies handle incident reporting, while the African Union Commission has a role in implementing the Malabo Convention.

What is missing is a public record that allows citizens to see how often each provider loses customers’ money and how often it gives that money back.

Central banks in major mobile money markets should publish annual fraud figures by channel and provider, showing complaints, losses and reimbursement rates, while national identity authorities should also publish fraud rates for biometric verification and commission independent testing against synthetic identities, with the results made public.

Consumer protection organisations can build the evidence by filing complaints for victims whose transactions were authorised through impersonation or synthetic identity fraud, particularly savings-group treasurers. Savings-group federations should also document their own losses, since regulators are currently leaving much of that evidence uncollected.

Women’s financial inclusion organisations, on their part, can push providers towards group accounts with multiple authorisations and transaction limits, reducing the amount one compromised wallet can lose.

And where regulators refuse to recognise provider responsibility, consumer organisations should take carefully selected cases to court. One judgment establishing how liability works when a provider’s own verification system is defeated could change the rules for thousands of victims.

INTERPOL has shown how quickly AI is changing the fraud landscape. African regulators now have to decide whether the person who was fooled should continue to carry the entire cost when the technology doing the fooling has become better than the technology protecting the account.

See something wrong? Talk to us privately on WhatsApp.

Support Our Work

Change happens when informed citizens act together. Your support enables journalism that connects evidence, communities, and action for good governance.

Share Publication

Facebook
X
LinkedIn
WhatsApp

About the Author