








INTERPOL’s newly released African Cyberthreat Assessment Report 2026 highlights a defining shift in the threat landscape: Cybercrime has evolved from isolated incidents into an industrialized, borderless ecosystem. That conclusion closely aligns with FortiGuard Labs’s global observations and forecasts for 2026. Criminal groups now operate as coordinated enterprises rather than just individual threat actors, supported by specialized service providers, shared infrastructure, automated tools, and mature supply chains.
Fortinet’s FortiGuard Labs is proud to have provided telemetry and threat intelligence for the INTERPOL report, which draws on input from law enforcement and cybersecurity officials across 36 African member countries, as well as private-sector data and operational intelligence. The report provides a targeted intelligence assessment of cybercrime trends across Africa and illustrates how the global cybercrime economy continues to evolve.
Africa’s rapid digital growth has expanded access to financial services, government programs, healthcare, education, and commerce. However, it has also created opportunities for criminal groups to exploit weaknesses in digital adoption, security measures, legal systems, and investigative capabilities. According to the INTERPOL member country survey in the report, cybercrime now likely accounts for more than 30% of recorded crimes in Africa’s Western and Southern regions. Reported losses from cybercrime across the continent more than doubled between 2024 and 2025, increasing from $192 million to $484 million, with the number of identified victims rising from 35,000 to 87,000. INTERPOL highlights that inconsistent reporting suggests the true extent of these losses is likely much higher.
The most important finding is not any single number but the underlying structure behind these activities. Online scams frequently serve as a gateway to identity theft and financial fraud. Once credentials are stolen, they can be used to access financial accounts, digital wallets, cloud services, and government platforms. Business email compromise continues to be one of the most financially damaging outcomes, while Cybercrime-as-a-Service platforms provide sophisticated tools and infrastructure to criminals with limited technical expertise.
This is how cybercrime becomes an industry. Access brokers, malware developers, botnet operators, money mules, scam centers, and ransomware affiliates all play specialized roles within this criminal ecosystem. Their activities easily cross borders, whereas investigators face diverse laws, reporting protocols, and evidence-sharing procedures. This asymmetry gives adversaries both agility and a strategic advantage.
Artificial intelligence is accelerating this industrious model. The INTERPOL survey found that 55% of cybercrime cases observed in 2025 involved AI in some capacity, with AI used occasionally in 47% and frequently in 8%. Criminals leverage AI throughout the attack process, from reconnaissance and phishing to extortion and evasion. They utilize AI to produce convincing deepfakes, craft hyper-personalized social engineering lures, generate synthetic identities that can bypass Know-Your-Customer checks, and modify malicious code to evade detection. Gone are the days where it was easy to spot an attack because of grammatical issues and poorly designed templates.
AI doesn’t need to create an entirely new class of attack to change the risk equation. Its immediate impact is on increasing throughput, enabling adversaries to perform known malicious activities more quickly, at greater scale, and with more personalized approaches. For example, scam operators can reach more victims, access brokers can more efficiently sort and enrich stolen credentials, and ransomware affiliates can automate many steps, from gaining initial access to executing extortion.
The Fortinet 2026 Global Threat Landscape Report reflects the same acceleration. FortiGuard intelligence found that the time-to-exploit for critical outbreaks has shrunk to 24 to 48 hours, a significant decrease from the previous average of 4.76 days. Additionally, FortiRecon adversary intelligence identified 7,831 confirmed ransomware victims worldwide, marking a 389% increase year-over-year. Advancements in AI-driven offensive tools and crime-service kits are making it easier for criminals to operate, reducing skill barriers and speeding up workflows. Overall, the integration of automation, specialization, and reusable infrastructure poses a greater threat than any individual tool.
The report also underscores why identity must be treated as a central security concern. Many of the threat chains it documents begin with credential harvesting or social engineering and end with account takeover, payment fraud, data theft, or ransomware. In Central Africa, FortiGuard Labs telemetry identified Cameroon as the second-highest hotspot for botnet detections on the continent, with 40.5 million detections in 2025. The report connects this activity to widespread device compromises used for credential harvesting and ransomware distribution.
At the same time, synthetic identities are complicating the identity problem. Criminals can merge genuine personal data with fabricated elements to open accounts, secure mobile loans, register SIM cards, and bypass verification methods. This undermines trust not just in passwords and credentials, but also in documents, images, voices, and behavioral signals used for identity verification.
Organizations should respond by making identity part of every security workflow rather than treating it as a separate access-control step. This involves safeguarding both human and non-human identities, enforcing least privilege principles, employing strong, phishing-resistant authentication methods when feasible, monitoring for exposed credentials and cybercriminal activities on the dark web, and combining identity signals with data from network, endpoint, cloud, and application sources. As attackers increasingly operate at machine speed, fragmented visibility hampers defenders’ ability to respond quickly, a result that is no longer acceptable.
The same principle applies to detection and response. Defenders need to convert intelligence into protection as quickly as adversaries convert information into attacks. This requires integrated security operations that continuously identify changes in exposure, validate active threats, assess the most exploitable risks, and automate containment where appropriate. While AI can help make these workflows more efficient, it must be based on high-quality intelligence and overseen by experienced analysts.
INTERPOL highlights that investing in AI tools should go hand-in-hand with investment in AI literacy. According to the report, only 8% of intelligence analysts in member countries possess advanced AI skills, while 92% of agencies see a lack of technical knowledge as their primary barrier to AI adoption. Investigators must understand how adversaries exploit synthetic voices, forged identities, deepfakes, and automated phishing. This awareness is equally essential for both security teams and private-sector employees, as the human element remains crucial even in automated attacks.
This is not solely a technology challenge. It’s also an operating-model challenge. Intelligence must move quickly between the teams, organizations, and jurisdictions able to act on it. Workflows must be in place prior to a crisis. And technical data must be converted into evidence and clear operational guidance for law enforcement, infrastructure providers, financial institutions, and security teams.
INTERPOL’s report formally calls for enhanced collaboration between public and private sectors, and advocates for building stronger information-sharing channels among law enforcement, telecoms, fintech, financial institutions, and cybersecurity entities. Such partnerships must be governed by clear agreements, specified data-retention policies, trusted procedures, and mutual accountability. Relying on ad hoc requests is too slow to keep up with criminal operations that can shift infrastructure, funds, and victims across borders within hours. It is imperative that law enforcement as well as industry make as many natural connections as possible via old fashioned networking. This ensures relationships and roles are already established when a problem arises during high profile events, so first responders can cut the noise and know who to speak with immediately.
Private-sector organizations can contribute global telemetry, infrastructure visibility, malware analysis, indicators of compromise, and specialized technical expertise. Law enforcement brings investigative authority, international coordination, and the ability to translate intelligence into arrests, seizures, and prosecutions. When these capabilities are integrated through formal mechanisms, sharing intelligence becomes a pathway to disruption rather than an end in itself.
Fortinet’s collaboration with INTERPOL highlights the potential of this model. Fortinet is a longstanding INTERPOL partner and an active member of its Global Cybercrime Expert Group, joining the INTERPOL Gateway initiative in 2018. During Operation Serengeti 2.0 in 2025, Fortinet provided indicators of compromise, command-and-control infrastructure data, and forensic insights to support coordinated international efforts. The operation resulted in 1,209 arrests, the dismantling of 11,432 malicious infrastructures, the recovery of $97.4 million, and the identification of nearly 88,000 victims.
Fortinet is also a founding member and active contributor to the World Economic Forum’s Cybercrime Atlas, which maps criminal ecosystems and identifies points where coordinated intervention can have systemic impact. Efforts such as the Cybercrime Atlas and INTERPOL-led operations show that public-private partnerships should be viewed as ongoing operational capabilities. The aim is not just to map criminal activity, but to conduct coordinated disruption at multiple points across the criminal ecosystem, increase the cost and risk of criminal activity, and hold more offenders accountable.
The African Cyberthreat Assessment Report 2026 provides a regional perspective on a globally pervasive issue. AI is accelerating the speed and efficiency of a cybercrime economy that is already organized, transnational, and service-driven. The most effective response isn’t merely a set of isolated defensive steps but a coordinated framework that combines security measures, machine-speed intelligence, robust identity management, skilled personnel, and reliable partnerships capable of turning insights into action.
Security leaders need to focus on shortening the interval between threat detection and response. Governments and law enforcement must enhance investigative capabilities, streamline cross-border procedures, and formalize cooperation with the private sector. And the cybersecurity industry needs to persist in sharing actionable intelligence and providing expertise to operations that create tangible disruption. Long-term progress hinges on how well these three groups collaborate to match the scale, speed, and coordination of the criminal ecosystems they face.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。