
According to the 2026 African Cyberthreat Assessment Report, published in June by INTERPOL, artificial intelligence is now involved in 55% of cybercrimes recorded on the continent. From scam centers and ransomware to deepfakes and synthetic identities, African cybercrime has evolved into an industrialized, cross-border ecosystem, with financial losses more than doubling in a single year. Here is a breakdown of the report's key figures and what they mean for the Democratic Republic of the Congo.
Published in June 2026 by INTERPOL’s Cybercrime Directorate, the African Cyberthreat Assessment Report 2026 is based on responses from 36 of the 49 African member countries surveyed—a 73% response rate—cross-referenced with data from private partners such as Fortinet, Mastercard, the Shadowserver Foundation, S2W, and TrendAI. Across its 40 pages, INTERPOL delivers a blunt assessment: cybercrime "has shifted from isolated incidents to an industrialized, borderless ecosystem."
The context partly explains this evolution. According to GSMA data cited by INTERPOL, Africa had over 1.1 billion mobile subscriptions and approximately 570 million internet users in 2025, with more than $1.1 trillion in digital transactions. This rapid digital adoption has outpaced the development of cybersecurity infrastructure, regulatory frameworks, and institutional capacity, creating fertile ground for criminal exploitation.
This is the report's most striking figure: between 2024 and 2025, losses linked to cybercrime in Africa rose from $192 million to $484 million, more than doubling in just one year. The number of identified victims jumped from 35,000 to 87,000 over the same period, driven primarily by AI-facilitated scams, credential theft, and automated social engineering campaigns. Including unreported losses, INTERPOL estimates that cybercrime cost the African economy at least $5 billion in 2025, compared to the $15.3 billion the continent spends globally on cybersecurity.
Online scams, fueled by mobile money platforms, social media, and AI, remain the most reported type of cybercrime. Notably, 72% of the countries surveyed report the presence of "scam centers" within their borders, with the highest concentrations in Southern and West Africa. These centers, often linked to human trafficking, sometimes hold victims against their will to force them to participate in fraudulent operations.
According to INTERPOL’s survey of member countries, 55% of cybercrime cases recorded in 2025 involved AI in some capacity. Criminals are using it to automate every stage of an attack: target reconnaissance, personalized phishing, extortion, and evasion of detection.
Two trends illustrate this shift. First, digital sextortion, fueled by deepfakes and synthetic content: TrendAI recorded approximately 600,000 detections of sextortion in Africa in 2025, primarily originating from South Africa (30%), Kenya (13%), and Côte d'Ivoire (11%). Second, Business Email Compromise (BEC), which has become significantly more sophisticated thanks to AI-generated emails that mimic a leader's tone, jargon, and signature style with near-perfect accuracy.
Another concerning development noted in the report is that criminals are no longer just stealing existing credentials. They are now creating entire synthetic identities, combining real personal data with AI-generated elements, capable of bypassing advanced biometric verification systems. These identities have been used to open bank accounts, obtain mobile loans, and register SIM cards under false identities.
The report identifies Central and West Africa as the regions with the highest rates of human-factor incidents, with up to 75% linked to employee behavior. In this predominantly French-speaking zone, Business Email Compromise campaigns and romance scams have proliferated, often via phishing messages in French targeting both businesses and individuals.
Cameroon has emerged as the second-largest hub for botnet detection in Africa, with 40.5 million incidents recorded in 2025 by FortiGuard Labs, signaling a vast network of compromised devices used for credential theft and ransomware distribution. Gabon and the Republic of the Congo show the highest detection rates for vulnerabilities in the sub-region. INTERPOL also notes that ransomware activity remains seemingly low there, likely due to underreporting rather than a genuine lack of threat, as actors prioritize discretion and long-term data exfiltration over immediate extortion.
The INTERPOL report does not detail specific statistics for the Democratic Republic of the Congo, as the country is not explicitly named in this 2026 edition. However, the DRC falls within the "Central Africa" sub-region, where the trends described above—BEC, romance scams, botnets, and incident underreporting—provide a relevant context for Congolese digital stakeholders.
At the national level, the DRC has taken several steps in recent months. On June 27, 2025, it became the nineteenth state to ratify the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), according to CIO Mag. In October 2025, the Congolese Minister of Digital Economy also signed the new United Nations Convention against Cybercrime, adopted in Hanoi, as reported by the Congolese Press Agency (ACP). Since 2022, the country has had a National Cybersecurity Strategy, which is approaching its 2022–2025 expiration date and will need to be renewed.
These advances come as several Congolese media outlets, including Actualite.cd and Numerico.cd, report an increase in digital attacks targeting institutions, businesses, and individuals in the DRC, including cases of bank account hacking, online fraud, and the spread of malware. In October 2025, the Congolese government had to deny rumors of a cyberattack targeting the country's critical institutions, according to Congo Quotidien. From a legal perspective, the specialized site Droit-Numérique.cd points out that the DRC does not yet have legislation specifically designed to effectively combat cybercrime, despite these recent international ratifications.
This situation illustrates a tension identified across the continent by the INTERPOL report: growing adherence to international and regional legal instruments does not always immediately translate into operational national legislation or sufficient investigative capacity.
The INTERPOL report is clear on one point: the speed at which cybercriminals are adopting artificial intelligence currently outpaces the ability of African institutions to adapt. "AI automates every stage of a cyberattack, from reconnaissance and phishing to extortion and evasion," summarizes Neal Jetton, Director of Cybercrime at INTERPOL, who nonetheless highlights a reason for optimism: "when countries work together, cybercriminal infrastructure can be identified, disrupted, and dismantled."
For the DRC, as for its neighbors in Central Africa, the challenge is no longer just to legislate, but to acquire the human, technical, and regional cooperation resources necessary to turn these texts into real protection for citizens, businesses, and institutions. In the meantime, individual vigilance—distrust of suspicious links, urgent money transfer requests, and content that seems too good to be true—remains the first line of defense.
Contact us
other articles

