Reported cybercrime losses in Africa didn’t creep up last year. They went from $192 million to $484 million, more than double, and Interpol‘s new report puts a specific cause on the jump: AI now shows up in 55 percent of reported cybercrimes on the continent.
That’s the number worth sitting with. Not a projection, not a survey of what security teams fear is coming. It’s a share of cases already logged, drawn from data across 36 African countries.
2025 is the year the tool became the operator
Interpol frames 2025 as a threshold. Before it, AI was something criminals used to work faster. After it, the agency calls AI the “core operational driver of cybercrime in Africa” on the continent.
The distinction isn’t semantic. A useful tool speeds up an existing crew. An operational driver changes what a crew of that size can attempt at all.
“AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion,” said Neal Jetton, head of Interpol’s cybercrime unit.
Deepfake extortion at a scale that’s hard to picture
About 600,000 cases of digital extortion involving deepfakes were recorded. That’s the figure that reframes everything else in the report, because extortion at that volume isn’t a targeted operation. It’s throughput.
Synthetic identities are doing similar work on the fraud side. The report notes they’re being generated well enough to get past biometric systems, which is the part that should worry anyone who has spent the past few years being told a face scan or a voice print is the sturdy replacement for a password.
Every stage of the attack chain is affected, per Jetton’s description. Reconnaissance. Phishing. Extortion. Evasion. There’s no single weak link to harden, which is exactly why the loss figure moved the way it did.
Enforcement is landing hits, but check the ratio
The report doesn’t read as pure alarm. Four Interpol-coordinated operations across 2025 and 2026 produced more than 1,500 arrests and the seizure of over $100 million.
That’s real work, and $100 million recovered is not a rounding error. But set it against $484 million in reported losses for the period and the math tells you where things stand. Enforcement is clawing back a fraction while the losses compound.
And $484 million only counts what got reported. Anyone who has watched fraud statistics knows reported losses trail actual ones, usually by a lot, and that gap tends to widen when the attacks are automated and individually small.
What to take from the numbers
If you run security anywhere that treats biometrics as a settled question, the synthetic identity finding is the line to act on. Interpol is describing systems being bypassed now, in cases already counted, not a lab demonstration.
The 55 percent figure is the one to track next. It’s the measure that separates a bad year from a structural shift, and 36 countries’ worth of data is enough of a base to watch it move.